Products: 1
Vulnerabilities: 46
Known Exploited: 0
4
Critical Level Threats
14
High Level Threats
26
Medium Level Threats
2
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2008-4687
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.
Last Modified: Apr 23, 2026
Published: Oct 22, 2008
CVE-2008-4688
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.
Last Modified: Apr 23, 2026
Published: Oct 22, 2008
CVE-2008-4689
mantis: logout without unsetting session cookie
Last Modified: Apr 23, 2026
Published: Sep 26, 2008
CVE-2008-3333
mantis: arbitrary file inclusion through user preferences page
Last Modified: Apr 23, 2026
Published: Jun 17, 2008
CVE-2008-3331
mantis: XSS in return_dynamic_filters.php
Last Modified: Apr 23, 2026
Published: May 20, 2008
Items Per Page
