MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
Description
Published to the GitHub Advisory Database
May 11, 2026
Reviewed
May 11, 2026
Published by the National Vulnerability Database
May 22, 2026
Last updated
Jun 8, 2026
Incorrect escaping of a saved filter's owner allows an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON.
Impact
Cross-site scripting (XSS).
Note that By default, only users with Manager access level or above can save their filters publicly
Patches
Workarounds
$g_ show_user_realname = OFF;in configuration)g_stored_query_create_threshold/ $g_stored_query_create_shared_thresholdtoNOBODYCredits
Thanks to siunam (Tang Cheuk Hei) for discovering and responsibly reporting the issue.
References