Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p6fr-rxq7-xcg8 | MantisBT Vulnerable to Stored XSS in File Download |
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mantisbt
Mantisbt mantisbt |
|
| Vendors & Products |
Mantisbt
Mantisbt mantisbt |
Thu, 28 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in 2.28.2. | |
| Title | MantisBT: Stored XSS in File Download | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T14:50:03.745Z
Reserved: 2026-05-07T16:20:08.658Z
Link: CVE-2026-44657
Updated: 2026-05-29T14:49:56.539Z
Status : Deferred
Published: 2026-05-28T21:16:31.053
Modified: 2026-05-29T15:11:03.853
Link: CVE-2026-44657
No data.
OpenCVE Enrichment
Updated: 2026-05-28T22:30:27Z
Github GHSA