MantisBT has Stored XSS on Move Attachments Admin Page
Description
Published to the GitHub Advisory Database
May 11, 2026
Reviewed
May 11, 2026
Published by the National Vulnerability Database
May 28, 2026
Last updated
Jun 9, 2026
Unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator access level) to inject HTML in Move Attachments admin page.
Impact
Cross-site scripting (XSS).
This is mitigated by Content Security Policy which restricts scripts execution.
Patches
Workarounds
None
References