Mantisbt is a widely deployed open-source issue-tracking and project-management platform whose modest product portfolio belies its prominence across academic, enterprise, and developer communities. The vulnerability profile centers on a single, self-contained application and clusters around web-tier weakness classes including cross-site scripting, SQL injection, improper input validation, and information exposure—typical of server-side web applications where user-supplied data enters both database queries and HTML rendering. A moderate tendency toward public exploit availability characterizes the vendor's disclosures. Defenders should prioritize patches for this category of flaw given the platform's role in handling project metadata and credentials; current severity, exploitation activity, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mantisbt over time
Signals from CVEs in this vendor scope (127 CVEs).
127 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7615HIGH MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. | Apr 16, 2017 | 8.8 | 92 | NO | YES |
CVE-2014-7146HIGH The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an | Nov 18, 2014 | 7.5 | 64 | NO | YES |
CVE-2014-8598MEDIUM The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive | Nov 18, 2014 | 6.4 | 54 | NO | YES |
CVE-2019-15715HIGH MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution. | Oct 9, 2019 | 7.2 | 52 | NO | YES |
CVE-2017-7309MEDIUM A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permi | Mar 31, 2017 | 4.8 | 49 | NO | NO |
CVE-2022-28508MEDIUM An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input f | May 4, 2022 | 6.1 | 33 | NO | YES |
CVE-2026-30849CRITICAL Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in | Mar 23, 2026 | 9.8 | 32 | NO | NO |
CVE-2020-28413MEDIUM In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP. | Dec 30, 2020 | 6.5 | 32 | NO | YES |
CVE-2017-7620MEDIUM MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substri | May 21, 2017 | 6.5 | 32 | NO | YES |
CVE-2014-2238MEDIUM SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitra | Mar 5, 2014 | 6.5 | 30 | NO | YES |
Signals from CVEs in this vendor scope (127 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mantisbt.
Media articles that mention a CVE ID that affects a product developed by Mantisbt — matched by CVE ID, not by vendor name.