Storyline
Multiple medium and high severity vulnerabilities found in MantisBT
MantisBT, a widely used issue tracking system, has been found vulnerable to several security issues including multiple authorization bypasses, stored cross-site scripting (XSS), content security policy (CSP) bypass, and privilege escalation.
Published 2026-05-11 17:58 UTCUpdated 2026-05-11 19:35 UTC
Current brief openSource links open
This current storyline is open here with summary, metadata, source links, continuity context, and full evidence. Paid is for compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (1 domains)domains are deduped. counts indicate coverage, not truth.1 top source shown
limited source diversity in top sources
Overview
MantisBT, a widely used issue tracking system, has been found vulnerable to several security issues including multiple authorization bypasses, stored cross-site scripting (XSS), content security policy (CSP) bypass, and privilege escalation.
Score total
1.49
Momentum 24h
12
Posts
12
Origins
1
Source types
1
Duplicate ratio
0%
Why now
- Multiple advisories were published simultaneously, indicating coordinated disclosure.
- High severity issues demand immediate attention from MantisBT users and administrators.
- Prompt patching can prevent exploitation of these vulnerabilities.
Why it matters
- MantisBT vulnerabilities expose private issue data and attachments to unauthorized users.
- Stored XSS and CSP bypasses can lead to account takeover and further compromise.
- Privilege escalation risks increase the impact of attacks on affected systems.
Continuity snapshot
- Trend status: insufficient_history.
- Continuity stage: seed.
- Current status: open.
- 12 current source-linked posts are attached to this storyline.
All evidence
All evidence
MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
github_advisories · github.com · 2026-05-11 19:35 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 1Origin domains: 1Duplicates: -
Showing 1 / 0
Top publishers (this list)
- github_advisories (1)
Top origin domains (this list)
- github.com (1)