mantisbt/mantisbt vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the mantisbt/mantisbt package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Cross-site Scripting (XSS)

<1.3.1
  • M
Cross-site Scripting (XSS)

<1.3.9>=2.0.0, <2.1.3>=2.2.0, <2.2.3
  • M
Cross-site Scripting (XSS)

<1.3.8>=2.0.0, <2.1.2>=2.2.0, <2.2.2
  • M
Cross-site Scripting (XSS)

<2.25.5
  • M
Cross-site Scripting (XSS)

>=2.0.0, <2.5.2
  • M
Cross-site Scripting (XSS)

<1.3.9>=2.1.0, <2.1.3>=2.2.0, <2.2.3
  • M
Cross-site Scripting (XSS)

>=0.0.0
  • M
Cross-site Scripting (XSS)

>=2.3.0, <2.3.2
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.17.2
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.17.2
  • M
Cross-site Scripting (XSS)

<1.3.12>=2.0.0, <2.5.2
  • H
Missing Authorization

<2.24.4
  • M
Insecure Storage of Sensitive Information

<2.24.4
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.15.1
  • M
Cross-site Scripting (XSS)

>=2.0.0, <2.15.1
  • M
Cross-site Scripting (XSS)

<2.25.0
  • M
Incorrect Authorization

<2.24.4
  • H
CSV Injection

<2.25.3
  • H
Incorrect Authorization

<2.24.4
  • M
Cross-site Scripting (XSS)

<2.25.2
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.24.2
  • M
Cross-site Scripting (XSS)

<2.21.3
  • M
Cross-site Scripting (XSS)

<2.21.2
  • M
Cross-site Scripting (XSS)

>=2.23.0, <2.24.3
  • H
Command Injection

<1.3.20>=2.0.0, <2.22.1
  • M
SQL Injection

<2.24.4
  • M
Incorrect Authorization

<2.24.3
  • M
Cross-site Request Forgery (CSRF)

<1.3.11>=2.0.0, <2.3.3>=2.4.0, <2.4.1
  • H
Weak Password Recovery Mechanism for Forgotten Password

>=1.3.0-rc.2, <1.3.10>=2.0.0, <2.2.4>=2.3.0, <2.3.1
  • M
Insecure Direct Object References

<2.26.4
  • M
Cross-site Scripting (XSS)

<2.26.2
  • H
Authentication Bypass Using an Alternate Path or Channel

<2.26.2
  • M
Exposure of Sensitive Information to an Unauthorized Actor

<2.26.2
  • M
Cross-site Scripting

<2.24.3
  • H
Authentication Bypass

<2.26.1
  • M
Information Exposure

<2.25.8
  • M
Information Exposure

<2.25.6