PT-2026-39880 · Mantisbt+1 · Mantisbt+1

Nozomu Sasaki

·

Published

2026-05-11

·

Updated

2026-05-20

·

CVE-2026-39960

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mantis Bug Tracker (MantisBT) versions prior to 2.28.2
Description Flawed logic in the Update Issue page 'bug update page.php' causes improper escaping of textarea custom field contents. This allows an authenticated user with low-privilege bug report permissions to inject HTML and potentially execute arbitrary JavaScript if Content-Security Policy (CSP) settings permit. Such execution can lead to session theft, administrative account takeover, and unauthorized access to full project data. Exploitation requires a textarea-type custom field to be configured for the project and affects any user viewing the bug edit form, including administrators.
Recommendations Update to version 2.28.2. Use the default Content-Security Policy to block script execution as a temporary workaround.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39960
GHSA-QJ6W-V29Q-4RGX

Affected Products

Mantisbt
Mantisbt/Mantisbt