logo

Critical 9.3 CVSS Auth Bypass and XSS Flaws Hit MantisBT

ID: 62f3a7ae-094f-5a5d-a2d0-c34e4547b437

STIX ID: report--62f3a7ae-094f-5a5d-a2d0-c34e4547b437

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed three vulnerabilities in MantisBT, including a critical authentication bypass (CVE-2026-30849, CVSS 9.3) that allows attackers to authenticate via the SOAP API on MySQL-compatible backends and two high-severity HTML injection/XSS issues (CVE-2026-33517, CVE-2026-33548); all versions up to 2.28.1 are affected and administrators are urged to apply patches or temporary mitigations such as disabling the SOAP API and sanitizing timeline/history entries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.