PT-2026-39881 · Mantisbt · Mantisbt

Published

2026-05-11

·

Updated

2026-05-23

·

CVE-2026-40596

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions MantisBT (affected versions not specified)
Description An authenticated user can inject arbitrary HTML by updating the font family of their account. This leads to cross-site scripting, where the injected payload is reflected on every page of the application. If combined with a Content Security Policy (CSP) bypass—a security layer that prevents the loading of malicious scripts—this could lead to account takeover.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-40596
GHSA-J3V9-553H-X28J

Affected Products

Mantisbt