Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-73vx-49mv-v8w5 | MantisBT has Stored HTML Injection/XSS when displaying Tags in Timeline |
Wed, 25 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mantisbt:mantisbt:2.28.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 24 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mantisbt
Mantisbt mantisbt |
|
| Vendors & Products |
Mantisbt
Mantisbt mantisbt |
Mon, 23 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (my_view_page.php) allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript, when displaying a tag that has been renamed or deleted. Version 2.28.1 contains a patch. Workarounds include editing offending History entries (using SQL) and wrapping `$this->tag_name` in a string_html_specialchars() call in IssueTagTimelineEvent::html(). | |
| Title | MantisBT has Stored HTML Injection / XSS when displaying Tags in Timeline | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T16:06:54.776Z
Reserved: 2026-03-20T18:05:11.832Z
Link: CVE-2026-33548
Updated: 2026-03-24T16:06:44.920Z
Status : Analyzed
Published: 2026-03-23T20:16:27.687
Modified: 2026-03-25T13:55:15.557
Link: CVE-2026-33548
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:36:52Z
Github GHSA