CVE-2026-33548: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33548 is a stored HTML injection / Cross-Site Scripting (XSS) vulnerability in Mantis Bug Tracker (MantisBT) affecting version 2.28.0. The flaw exists in the Timeline view (my_view_page.php), where tag names retrieved from issue history are not properly escaped, allowing an attacker to inject arbitrary HTML and, if Content Security Policy (CSP) settings permit, execute arbitrary JavaScript. It was discovered by Vishal Shukla, responsibly disclosed, and published on March 23, 2026. The patched version is 2.28.2 (also referenced as 2.28.1 in some sources). The vulnerability carries a CVSS v3.1 score of 6.1 (Medium) and a CVSS v4.0 score of 8.6 (High) (GitHub Advisory, MantisBT Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability resides in IssueTagTimelineEvent::html() within core/classes/IssueTagTimelineEvent.class.php. When the Timeline API retrieves tag data from the bug_history table, it may encounter tag names that no longer exist (e.g., because the tag was renamed or deleted). In this fallback path, the raw $this->tag_name value was rendered directly into the HTML output without HTML-encoding, enabling injection of arbitrary markup. The fix wraps the fallback value in a string_html_specialchars() call: changing $this->tag_name to string_html_specialchars( $this->tag_name ) (Patch Commit, GitHub Advisory). Exploitation requires low-level privileges (sufficient to create or rename tags) and passive user interaction (a victim viewing the Timeline page).

Impact

Successful exploitation allows an attacker to inject malicious HTML and, where CSP does not block inline scripts, execute arbitrary JavaScript in the context of a victim user's browser session. Potential consequences include session hijacking, credential theft, and unauthorized actions performed on behalf of the victim within the MantisBT application. The vulnerability affects the confidentiality and integrity of the vulnerable system; availability is not directly impacted (GitHub Advisory, MantisBT Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.046% (15th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.

Exploitation steps

  1. Obtain low-privilege access: Log in to a MantisBT 2.28.0 instance with an account that has sufficient permissions to create or manage tags.
  2. Create a malicious tag: Create a new tag with a name containing an HTML/JavaScript payload, e.g., <img src=x onerror=alert(document.cookie)>.
  3. Apply the tag to an issue: Attach the malicious tag to one or more issues so that the action is recorded in the bug_history table.
  4. Trigger the fallback path: Rename or delete the tag. This causes tag_get_by_name() in IssueTagTimelineEvent::html() to return false, forcing the code to fall back to displaying the raw stored tag name from history.
  5. Deliver the payload: Wait for or socially engineer a target user (e.g., a project manager or administrator) to visit the Timeline view (my_view_page.php). When the page renders, the unescaped tag name is injected into the HTML, executing the JavaScript payload in the victim's browser if CSP permits.
  6. Harvest results: The executed script can steal session cookies, perform actions on behalf of the victim, or exfiltrate data from the MantisBT instance (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Logs: Web server access logs showing requests to my_view_page.php from unusual IP addresses or at unusual times, particularly correlated with tag rename/delete events in the MantisBT audit log.
  • Database: Entries in the bug_history table where the tag name field contains HTML special characters (<, >, ", ') or JavaScript keywords (e.g., script, onerror, alert, document.cookie).
  • Network: Unexpected outbound HTTP requests from victim browsers to attacker-controlled domains shortly after viewing the MantisBT Timeline page (indicative of data exfiltration via injected script).
  • Application: MantisBT tag history records showing tags that were created with unusual names and subsequently renamed or deleted in a short timeframe.

Mitigation and workarounds

Upgrade MantisBT to version 2.28.2 (patched), which applies the fix in commit f32787c that wraps $this->tag_name in string_html_specialchars() within IssueTagTimelineEvent::html() (GitHub Advisory, Patch Commit). If immediate upgrade is not possible, two workarounds are available: (1) manually edit offending bug_history table entries using SQL to remove or sanitize malicious tag name values; and (2) apply the one-line code fix directly by wrapping $this->tag_name in string_html_specialchars() in core/classes/IssueTagTimelineEvent.class.php. Additionally, strengthening the application's Content Security Policy (CSP) to block inline script execution will reduce the risk of JavaScript execution even if HTML injection occurs.

Community reactions

The vulnerability was responsibly disclosed by security researcher Vishal Shukla (GitHub: shukla304) and credited in the official MantisBT advisory. The MantisBT maintainer dregad handled remediation and published the advisory on March 23, 2026 (MantisBT Advisory). No significant broader media coverage or notable community commentary beyond the official advisory and standard vulnerability database entries has been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management