HTML Injection Vulnerability in Mantis Bug Tracker 2.28.0
CVE-2026-33517
8.6HIGH
What is CVE-2026-33517?
In Mantis Bug Tracker version 2.28.0, an improper escaping of tag names during the deletion process allows attackers to inject malicious HTML. This could lead to the execution of arbitrary JavaScript if Content Security Policy (CSP) settings allow it. The issue is resolved in version 2.28.1. Users are encouraged to apply the update or use workarounds such as reverting a specific commit or editing language files to eliminate the exploitable placeholder.
Affected Version(s)
mantisbt = 2.28.0
