PT-2026-39881 · Mantisbt · Mantisbt

CVE-2026-40596

·

Published

2026-05-11

·

Updated

2026-05-23

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions MantisBT (affected versions not specified)
Description An authenticated user can inject arbitrary HTML by updating the font family of their account. This leads to cross-site scripting, where the injected payload is reflected on every page of the application. If combined with a Content Security Policy (CSP) bypass—a security layer that prevents the loading of malicious scripts—this could lead to account takeover.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40596
GHSA-9C3J-XM6V-J7J3
GHSA-J3V9-553H-X28J

Affected Products

Mantisbt