Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mantisbt

First CVE: Sep 24, 2008Active for: 18 yearsTotal CVEs: 127
38.9
VTI Score
Medium

Mantisbt is a widely deployed open-source issue-tracking and project-management platform whose modest product portfolio belies its prominence across academic, enterprise, and developer communities. The vulnerability profile centers on a single, self-contained application and clusters around web-tier weakness classes including cross-site scripting, SQL injection, improper input validation, and information exposure—typical of server-side web applications where user-supplied data enters both database queries and HTML rendering. A moderate tendency toward public exploit availability characterizes the vendor's disclosures. Defenders should prioritize patches for this category of flaw given the platform's role in handling project metadata and credentials; current severity, exploitation activity, and exposure figures are shown alongside this summary.

FAUCET AI Generated
127
Total CVEs
More Total CVEs than 99% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mantisbt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 24, 2008
17 years ago
Most Recent CVE
Mar 23, 2026
123 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (127 CVEs).

127 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7615HIGH
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
Apr 16, 20178.892NOYES
CVE-2014-7146HIGH
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an
Nov 18, 20147.564NOYES
CVE-2014-8598MEDIUM
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive
Nov 18, 20146.454NOYES
CVE-2019-15715HIGH
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
Oct 9, 20197.252NOYES
CVE-2017-7309MEDIUM
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permi
Mar 31, 20174.849NONO
CVE-2022-28508MEDIUM
An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input f
May 4, 20226.133NOYES
CVE-2026-30849CRITICAL
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in
Mar 23, 20269.832NONO
CVE-2020-28413MEDIUM
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
Dec 30, 20206.532NOYES
CVE-2017-7620MEDIUM
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substri
May 21, 20176.532NOYES
CVE-2014-2238MEDIUM
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitra
Mar 5, 20146.530NOYES
View all 127 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products127 CVEs
10%
73%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.6%)
Network71 (55.9%)
Unknown54 (42.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low70 (55.1%)
High3 (2.4%)
Unknown54 (42.5%)
User Interaction
None30 (23.6%)
Unknown54 (42.5%)
Required43 (33.9%)
Privileges Required
Low24 (18.9%)
High8 (6.3%)
None41 (32.3%)
Unknown54 (42.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (127 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
3.1% of CVEs· 98th percentile
Nuclei
2 CVEs
1.6% of CVEs· 95th percentile
ExploitDB
10 CVEs
7.9% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mantisbt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mantisbt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mantisbt's Products

View all 3 CNAs →

Top CWEs