CVE-2026-40598

MEDIUM

MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page

Title source: cna
STIX 2.1

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-encode special characters, on some specific server configurations this could poison the cache, leading to cross-site scripting. This issue has been fixed in version 2.28.2.

Scores

CVSS v4 6.9
EPSS 0.0053
EPSS Percentile 40.2%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
mantisbt/mantisbt 0 - 2.28.2Packagist
mantisbt/mantisbt < 2.28.2
Published May 22, 2026
Tracked Since May 23, 2026