mantisbt/mantisbt Security Advisories for 2.26.0 (5)
- 
                        [MEDIUM] MantisBT vulnerable to information disclosure with user profilesPKSA-9rc9-dxmv-6ty7 CVE-2024-45792 GHSA-h5q3-fjp4-2x7r Affected version: <=2.26.3 Reported by: 
 GitHub
- 
                        [MEDIUM] Mantis Bug Tracker (MantisBT) vulnerable to cross-site scriptingPKSA-s5w7-qrwt-4ggd CVE-2024-34081 GHSA-wgx7-jp56-65mq Affected version: <2.26.2 Reported by: 
 GitHub
- 
                        [MEDIUM] MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized ActorPKSA-sqwp-pr85-66jc CVE-2024-34080 GHSA-99jc-wqmr-ff2q Affected version: <2.26.2 Reported by: 
 GitHub
- 
                        [HIGH] Mantis Bug Tracker (MantisBT) allows user account takeover in the signup/reset password processPKSA-vn99-1c14-x82z CVE-2024-34077 GHSA-93x3-m7pw-ppqm Affected version: <=2.26.1 Reported by: 
 GitHub
- 
                        [HIGH] MantisBT Host Header Injection vulnerabilityPKSA-h79w-zb4t-bjtf CVE-2024-23830 GHSA-mcqj-7p29-9528 Affected version: <2.26.1 Reported by: 
 GitHub