Skip to content
Threat Feed

Tag

Mantisbt

6 briefs RSS
high advisory

MantisBT Remote Code Execution via Class Hoisting (CVE-2026-49273)

A high-severity remote code execution vulnerability, CVE-2026-49273, affects MantisBT versions 2.28.3 and earlier, allowing an authenticated administrator to achieve arbitrary code execution as the web server user by leveraging PHP's class hoisting during the processing of non-string configuration values in `adm_config_set.php`.

MantisBT remote-code-execution web-application php class-hoisting xss web-vulnerability
1r 1t
critical advisory

MantisBT SOAP API Authentication Bypass and Privilege Escalation (CVE-2026-47156)

A critical authentication bypass vulnerability, CVE-2026-47156, exists in the SOAP API's mci_check_login() function of MantisBT versions 2.28.3 and earlier, allowing an unauthenticated attacker to impersonate any user, including an administrator, by knowing a valid cookie_string and the target username, without needing the target's password, which can lead to full administrator access, extensive data exfiltration, and destructive operations when default self-registration is enabled.

MantisBT authentication-bypass privilege-escalation web-vulnerability cve
2t
critical advisory

MantisBT SQL Injection via history_order Configuration Value

MantisBT versions 2.28.3 and earlier are vulnerable to a SQL injection within the `history_order` configuration value in `core/history_api.php`, allowing an authenticated administrator to inject malicious SQL via the web UI or REST API, which then executes whenever any user views a bug with history entries, leading to sensitive data extraction and potential Remote Code Execution (RCE) via webshell if the MySQL FILE privilege is enabled.

MantisBT <= 2.28.3 sql-injection web-application vulnerability rce mantisbt xss web-vulnerability credential-phishing
2r 8t
high threat

MantisBT Vulnerable to Stored XSS in File Download

MantisBT is vulnerable to stored cross-site scripting (XSS) via file_download.php by using the `show_inline=1` parameter with a valid CSRF token to upload a crafted XHTML attachment referencing a JavaScript attachment, leading to arbitrary code execution.

mantisbt/mantisbt xss mantisbt github advisory
2r 1t
high advisory

MantisBT Stored XSS Vulnerability via Tag Timeline Display

A stored HTML injection vulnerability (CVE-2026-33548) exists in MantisBT version 2.28.0, allowing attackers to inject HTML and execute arbitrary JavaScript by manipulating tag names displayed in the timeline due to improper escaping.

MantisBT xss html-injection cve-2026-33548 webserver
2r 1t
critical advisory

MantisBT Authentication Bypass via SOAP API on MySQL

MantisBT instances running on MySQL are vulnerable to an authentication bypass in the SOAP API due to improper type checking on the password parameter, allowing attackers with a valid username to log in without the actual password.

MantisBT authentication-bypass soap-api
3r 1t