CVE-2026-40607Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a saved filter's owner, allowing an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON. Note that By default, only users with Manager access level or above can save their filters publicly. This issue has been fixed in version 2.28.2. If developers are unable to update immediately, they can work around this issue by preventing display of users' real names (set $g_ show_user_realname = OFF; in configuration), and restricting the ability to store filters (set $g_stored_query_create_threshold / $g_stored_query_create_shared_threshold to NOBODY).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-23)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-11: 1Mentions · 2026-05-23: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-23: 205-1105-23
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-111
General1
2026-05-232
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40607 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a save… https://www.cve.org/CVERecord?id=CVE-2026-40607 ----- Traducción: CVE-2026-40607 Man… http://infoflow.cloud`

    Post summary

    The post announces a Stored XSS flaw (CVE‑2026‑40607) in Mantis Bug Tracker versions 2.11.0‑2.28.1, noting incorrect escaping—but it gives no exploitation details or patches.

    0000047
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40607 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a save… https://www.cve.org/CVERecord?id=CVE-2026-40607

    Post summary

    The post announces a stored XSS vulnerability in Mantis Bug Tracker for versions 2.11.0 to 2.28.1 caused by improper input escaping during data saving.

    00000198
    57.5K followersView on X
  • DailyCVE@dailycve
    General

    🔴 MantisBT, Stored XSS, #CVE-2026-40607 (High) https://dailycve.com/mantisbt-stored-xss-cve-2026-40607-high/

    Post summary

    The note announces a high‑severity Stored XSS flaw in MantisBT (CVE‑2026‑40607) but contains no further details or actionable information.

    0000035
    203 followersView on X

Explore more