Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the file MainWindow.UI.cs of the component Preview. The manipulation results in path traversal. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | MantisZip Preview MainWindow.UI.cs Path.Combine path traversal | |
| First Time appeared |
Mantiszip
Mantiszip mantiszip |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:mantiszip:mantiszip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mantiszip
Mantiszip mantiszip |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-24T02:45:13.557Z
Reserved: 2026-09-23T18:19:15.295Z
Link: CVE-2026-96884
No data.
Status : Received
Published: 2026-09-24T03:16:58.760
Modified: 2026-09-24T03:16:58.760
Link: CVE-2026-96884
No data.
OpenCVE Enrichment
Updated: 2026-09-24T05:00:13Z