๐Ÿ” CVE Alert

CVE-2026-44657

UNKNOWN 0.0

MantisBT: Stored XSS in File Download

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in 2.28.2.

CWE CWE-79
Vendor mantisbt
Product mantisbt
Published May 28, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for mantisbt mantisbt

Be the first to know when new unknown vulnerabilities affecting mantisbt mantisbt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

mantisbt / mantisbt
< 2.28.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mantisbt/mantisbt/security/advisories/GHSA-p6fr-rxq7-xcg8 github.com: https://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3 github.com: https://github.com/mantisbt/mantisbt/commit/26647b2e68ba30b9d7987d4e03d7a16416684bc2 mantisbt.org: https://mantisbt.org/bugs/view.php?id=37020