Количество 3
Количество 3
CVE-2026-33548
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (my_view_page.php) allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript, when displaying a tag that has been renamed or deleted. Version 2.28.1 contains a patch. Workarounds include editing offending History entries (using SQL) and wrapping `$this->tag_name` in a string_html_specialchars() call in IssueTagTimelineEvent::html().
CVE-2026-33548
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ...
GHSA-73vx-49mv-v8w5
MantisBT has Stored HTML Injection/XSS when displaying Tags in Timeline
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33548 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (my_view_page.php) allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript, when displaying a tag that has been renamed or deleted. Version 2.28.1 contains a patch. Workarounds include editing offending History entries (using SQL) and wrapping `$this->tag_name` in a string_html_specialchars() call in IssueTagTimelineEvent::html(). | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-33548 Mantis Bug Tracker (MantisBT) is an open source issue tracker. In vers ... | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
GHSA-73vx-49mv-v8w5 MantisBT has Stored HTML Injection/XSS when displaying Tags in Timeline | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу