Technology · Packagist
mantisbt/mantisbt (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 26 vulnerabilities in mantisbt/mantisbt (Packagist): 0 in the last 7 days and 9 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-47156, was published on 9 September 2026.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 3
- Exploited in the wild
- 0
About mantisbt/mantisbt (Packagist)
An open-source web-based bug tracking system written in PHP.
Latest mantisbt/mantisbt (Packagist) vulnerabilities
- CVE-2026-47156: MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP…criticalCVSS 9.3EPSS 0.7%
- CVE-2026-62944: MantisBT stored XSS in print_all_bug_page_word.phphighCVSS 8.6
- CVE-2026-52883: MantisBT improper input validation in REST and SOAP APIsmediumCVSS 5.3
- CVE-2026-52882: MantisBT authorization bypass in REST and SOAP APIsmediumCVSS 5.3
- CVE-2026-52881: MantisBT reflected XSS in admin/install.phpcriticalCVSS 9.2
- CVE-2026-52847: MantisBT reflected XSS in admin/install.phpcriticalCVSS 9.2
- CVE-2026-49280: MantisBT unauthorized issue status change in REST and SOAP APImediumCVSS 5.3
- CVE-2026-49273: MantisBT remote code execution in adm_config_set.phphighCVSS 8.6
- CVE-2026-47142: MantisBT SQL injection in history_order configurationhighCVSS 8.5
- CVE-2026-44657: MantisBT stored XSS in file_download.php via XHTML attachmentshighCVSS 7.5EPSS 0.1%
- CVE-2026-44655: MantisBT stored XSS in Move Attachments admin pagehighCVSS 8.6EPSS 0.1%
- CVE-2026-42071: MantisBT missing authorization check in file visibility functionhighCVSS 7.2EPSS 0.1%
- CVE-2026-42070: MantisBT authorization bypass in mc_issue_update APImediumCVSS 5.3EPSS 0.0%
- CVE-2026-41897: MantisBT reflected XSS in return_dynamic_filters.phpmediumCVSS 5.3EPSS 0.1%
- CVE-2026-40598: MantisBT HTML injection in tag update pagemediumCVSS 6.9EPSS 0.4%
- CVE-2026-40597: MantisBT Content Security Policy bypass in file_download.phphighCVSS 7.6EPSS 0.5%
- CVE-2026-40596: MantisBT stored XSS in user font family preferencehighCVSS 7.2EPSS 0.4%
- CVE-2026-39960: MantisBT stored XSS in textarea custom fieldsmediumCVSS 5.4EPSS 0.0%
- CVE-2026-34970: MantisBT information disclosure in bugnote revisions pagemediumCVSS 5.3EPSS 0.0%
- CVE-2026-34754: MantisBT improper access control in REST API attachment uploadmediumCVSS 4.3EPSS 0.0%
- CVE-2026-34744: MantisBT authorization bypass in private issue attachmentsmediumCVSS 5.3EPSS 0.0%
- CVE-2026-34579: MantisBT authorization bypass in private issue monitoringmediumCVSS 5.3EPSS 0.0%
- CVE-2026-34463: MantisBT stored XSS in bug_report_page.php via project namehighCVSS 8.6EPSS 0.0%
- CVE-2026-34390: MantisBT privilege escalation in ProjectUsersAddCommandmediumCVSS 5.1EPSS 0.0%
- CVE-2026-33052: MantisBT authorization bypass in global profile creationmediumCVSS 5.3EPSS 0.0%
Most severe mantisbt/mantisbt (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-47156: MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP…criticalCVSS 9.3EPSS 0.7%
- CVE-2026-52881: MantisBT reflected XSS in admin/install.phpcriticalCVSS 9.2
- CVE-2026-52847: MantisBT reflected XSS in admin/install.phpcriticalCVSS 9.2
- CVE-2026-44655: MantisBT stored XSS in Move Attachments admin pagehighCVSS 8.6EPSS 0.1%
- CVE-2026-34463: MantisBT stored XSS in bug_report_page.php via project namehighCVSS 8.6EPSS 0.0%
- CVE-2026-62944: MantisBT stored XSS in print_all_bug_page_word.phphighCVSS 8.6
- CVE-2026-49273: MantisBT remote code execution in adm_config_set.phphighCVSS 8.6
- CVE-2026-47142: MantisBT SQL injection in history_order configurationhighCVSS 8.5
- CVE-2026-40597: MantisBT Content Security Policy bypass in file_download.phphighCVSS 7.6EPSS 0.5%
- CVE-2026-44657: MantisBT stored XSS in file_download.php via XHTML attachmentshighCVSS 7.5EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 8 | 2 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/mantisbt-mantisbt.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "mantisbt/mantisbt (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/mantisbt-mantisbt, 26 September 2026.