MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
Description
Published to the GitHub Advisory Database
May 11, 2026
Reviewed
May 11, 2026
Last updated
May 11, 2026
Any authenticated user can inject arbitrary HTML via updating their account's font family.
Impact
Cross-site scripting.
The injected payload will be reflected in every MantisBT page.
Leveraging another vulnerability (CSP bypass, see GHSA-9c3j-xm6v-j7j3), the attacker could achieve account takeover.
Patches
Workarounds
None
Credits
Thanks to siunam (Tang Cheuk Hei) for discovering and responsibly reporting the issue.
References