Junglewise Threat Intelligence

CVE-2026-44655: MantisBT stored XSS in Move Attachments admin page

CVE-2026-44655 · Severity: high · CVSS 4 · Published 2026-05-28

Technologies: mantisbt/mantisbt (Packagist), MantisBT. Vendors: Packagist, MantisBT.

Executive brief

MantisBT, a popular open-source bug tracking system, is vulnerable to a security flaw where malicious code can be embedded into project names. If an administrator or manager creates a project with a specially crafted name, they can execute unauthorized scripts when other administrators visit the 'Move Attachments' management page. This could lead to unauthorized access to sensitive data or administrative actions being performed without the user's knowledge.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in MantisBT versions 1.3.0 through 2.28.1. The vulnerability is located in the 'Move Attachments' admin page, where project names are rendered without proper HTML escaping. An attacker with sufficient privileges to create or rename projects (typically Manager or Administrator) can inject malicious HTML/JavaScript into the project name field. When an administrator subsequently views the Move Attachments page, the payload executes in their browser context. While the impact is mitigated by the application's Content Security Policy (CSP), the vulnerability is addressed in version 2.28.2.

Affected products

  • MantisBT MantisBT >= 1.3.0, <= 2.28.1

Timeline

  • 2026-05-11: advisory: GitHub Advisory published
  • 2026-05-28: disclosed: NVD publication

References

Related threats