Known Vulnerabilities for products from Mantis
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Mantis".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44657 json | Not Provided | 2026-05-28 | 2026-05-29 | |
| CVE-2026-44655 json | Not Provided | 2026-05-28 | 2026-05-29 | |
| CVE-2026-42071 json | Not Provided | 2026-05-28 | 2026-05-29 | |
| CVE-2026-42070 json | Not Provided | 2026-05-28 | 2026-05-28 | |
| CVE-2026-41897 json | Not Provided | 2026-05-28 | 2026-05-28 | |
| CVE-2026-40607 json | Not Provided | 2026-05-22 | 2026-05-26 | |
| CVE-2026-40598 json | Not Provided | 2026-05-22 | 2026-05-23 | |
| CVE-2026-40597 json | Not Provided | 2026-05-22 | 2026-05-26 | |
| CVE-2026-40596 json | Not Provided | 2026-05-22 | 2026-05-22 | |
| CVE-2026-39960 json | Not Provided | 2026-05-20 | 2026-05-21 | |
| CVE-2008-4689 json | Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack ses... | Not Provided | 2008-10-22 | 2026-04-23 |
| CVE-2008-4688 json | core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue dat... | Not Provided | 2008-10-22 | 2026-04-23 |
| CVE-2008-4687 json | manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter ... | Not Provided | 2008-10-22 | 2026-04-23 |
| CVE-2008-3333 json | Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute ... | Not Provided | 2008-07-27 | 2026-04-23 |
| CVE-2008-3332 json | Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execu... | Not Provided | 2008-07-27 | 2026-04-23 |
| CVE-2008-3331 json | Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inje... | Not Provided | 2008-07-27 | 2026-04-23 |
| CVE-2008-0404 json | Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTM... | Not Provided | 2008-01-23 | 2026-04-23 |
| CVE-2007-6611 json | Cross-site scripting (XSS) vulnerability in view.php in Mantis before 1.1.0 allows remote attackers to inject arbitrary web s... | Not Provided | 2008-01-03 | 2026-04-23 |
| CVE-2006-6574 json | Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attacke... | Not Provided | 2006-12-15 | 2026-04-23 |
| CVE-2006-6515 json | Mantis before 1.1.0a2 sets the default value of $g_bug_reminder_threshold to "reporter" instead of a more privileged role, wh... | Not Provided | 2006-12-14 | 2026-04-23 |