PT-2026-39881 · Mantisbt · Mantisbt
Published
2026-05-11
·
Updated
2026-05-23
·
CVE-2026-40596
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
MantisBT (affected versions not specified)
Description
An authenticated user can inject arbitrary HTML by updating the font family of their account. This leads to cross-site scripting, where the injected payload is reflected on every page of the application. If combined with a Content Security Policy (CSP) bypass—a security layer that prevents the loading of malicious scripts—this could lead to account takeover.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mantisbt