Back

HIGH

MantisBT is vulnerable to XSS and potential account takeover via user font family preference update

Published May 22, 2026

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML by updating their account's font family. Upon exploitation, an XSS payload would be reflected on every MantisBT page. Leveraging another vulnerability (CSP bypass, see GHSA-9c3j-xm6v-j7j3), the attacker could achieve account takeover. This issue has been fixed in version 2.28.2.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 22, 2026
Updated May 22, 2026
Reserved Apr 14, 2026
CISA Vulnrichment
Updated May 22, 2026
NVD
Status Deferred
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-J3V9-553H-X28J