mantisbt/mantisbt vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the mantisbt/mantisbt package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
Cross-site Scripting (XSS)

<1.3.1
  • M
Cross-site Scripting (XSS)

<1.3.9>=2.0.0, <2.1.3>=2.2.0, <2.2.3
  • M
Cross-site Scripting (XSS)

<1.3.8>=2.0.0, <2.1.2>=2.2.0, <2.2.2
  • M
Cross-site Scripting (XSS)

<2.25.5
  • M
Cross-site Scripting (XSS)

>=2.0.0, <2.5.2
  • M
Cross-site Scripting (XSS)

<1.3.9>=2.1.0, <2.1.3>=2.2.0, <2.2.3
  • M
Cross-site Scripting (XSS)

>=0.0.0
  • M
Cross-site Scripting (XSS)

>=2.3.0, <2.3.2
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.17.2
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.17.2
  • M
Cross-site Scripting (XSS)

<1.3.12>=2.0.0, <2.5.2
  • H
Missing Authorization

<2.24.4
  • M
Insecure Storage of Sensitive Information

<2.24.4
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.15.1
  • M
Cross-site Scripting (XSS)

>=2.0.0, <2.15.1
  • M
Cross-site Scripting (XSS)

<2.25.0
  • M
Incorrect Authorization

<2.24.4
  • H
CSV Injection

<2.25.3
  • H
Incorrect Authorization

<2.24.4
  • M
Cross-site Scripting (XSS)

<2.25.2
  • M
Cross-site Scripting (XSS)

>=2.1.0, <2.24.2
  • M
Cross-site Scripting (XSS)

<2.21.3
  • M
Cross-site Scripting (XSS)

<2.21.2
  • M
Cross-site Scripting (XSS)

>=2.23.0, <2.24.3
  • H
Command Injection

<1.3.20>=2.0.0, <2.22.1
  • M
SQL Injection

<2.24.4
  • M
Incorrect Authorization

<2.24.3
  • M
Cross-site Request Forgery (CSRF)

<1.3.11>=2.0.0, <2.3.3>=2.4.0, <2.4.1
  • H
Weak Password Recovery Mechanism for Forgotten Password

>=1.3.0-rc.2, <1.3.10>=2.0.0, <2.2.4>=2.3.0, <2.3.1
  • M
Insecure Direct Object References

<2.26.4
  • M
Cross-site Scripting (XSS)

<2.26.2
  • H
Authentication Bypass Using an Alternate Path or Channel

<2.26.2
  • M
Exposure of Sensitive Information to an Unauthorized Actor

<2.26.2
  • M
Cross-site Scripting

<2.24.3
  • H
Authentication Bypass

<2.26.1
  • M
Information Exposure

<2.25.8
  • M
Information Exposure

<2.25.6