CVE-2018-13055: Mantisbt
Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.
Affected products
- Mantisbt Mantisbt: from 2.1.0, up to and including 2.15.0
Published 2018-08-03. Last modified 2026-06-17.