MantisBT before 1.3.10, 2.2.4, and 2.3.1 are vulnerable to unauthenticated password reset.
b841a48022b6fff1808993ef21d4fbe8a00fa654f48327de4ebf89027be87ffc
Mantis Bug Tracker version 2.3.0 suffers from a remote code execution vulnerability.
c5bd41082422ed338ccc46ee3ad8d43820a3a1cd833484f28da741205e12c069
Mantis Bug Tracker versions 1.3.0 and 2.3.0 suffer from a pre-authentication remote password reset vulnerability.
da0c10bca7d635dd4ba8a9cdd41f8f1b36c9490cffa05acee01ffcdf095d74d1