MantisBT is vulnerable to XSS and potential account takeover via user font family preference update
Published May 22, 2026
7.2
HIGHCVSS 4.0
EPSS 0.50%
Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML by updating their account's font family. Upon exploitation, an XSS payload would be reflected on every MantisBT page. Leveraging another vulnerability (CSP bypass, see GHSA-9c3j-xm6v-j7j3), the attacker could achieve account takeover. This issue has been fixed in version 2.28.2.
Affected products
-
- Version >= 2.11.0, < 2.28.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 22, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.50% (0.00499) | 40.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.50% (0.00499) | 38.60th | v5 (v2026.06.15) |
| May 23, 2026 | 0.05% (0.00050) | 15.75th | v4 (v2025.03.14) |
References (7)
- https://github.com/advisories/GHSA-j3v9-553h-x28j Advisory
- https://github.com/mantisbt/mantisbt/commit/9e8409cdd979eba86ef532756fc47c1d8112d22d x_refsource_MISC
- https://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3 x_refsource_MISC
- https://github.com/mantisbt/mantisbt/security/advisories/GHSA-j3v9-553h-x28j x_refsource_CONFIRM
- https://mantisbt.org/bugs/view.php?id=37011 x_refsource_MISC
- https://mantisbt.org/bugs/view.php?id=37016 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-40596
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-j3v9-553h-x28j | Advisory | |
| https://github.com/mantisbt/mantisbt/commit/9e8409cdd979eba86ef532756fc47c1d8112d22d | x_refsource_MISC | |
| https://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3 | x_refsource_MISC | |
| https://github.com/mantisbt/mantisbt/security/advisories/GHSA-j3v9-553h-x28j | x_refsource_CONFIRM | |
| https://mantisbt.org/bugs/view.php?id=37011 | x_refsource_MISC | |
| https://mantisbt.org/bugs/view.php?id=37016 | x_refsource_MISC | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40596 |
Change history (0)
No recorded changes yet.