
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33548 is a stored HTML injection / Cross-Site Scripting (XSS) vulnerability in Mantis Bug Tracker (MantisBT) affecting version 2.28.0. The flaw exists in the Timeline view (my_view_page.php), where tag names retrieved from issue history are not properly escaped, allowing an attacker to inject arbitrary HTML and, if Content Security Policy (CSP) settings permit, execute arbitrary JavaScript. It was discovered by Vishal Shukla, responsibly disclosed, and published on March 23, 2026. The patched version is 2.28.2 (also referenced as 2.28.1 in some sources). The vulnerability carries a CVSS v3.1 score of 6.1 (Medium) and a CVSS v4.0 score of 8.6 (High) (GitHub Advisory, MantisBT Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability resides in IssueTagTimelineEvent::html() within core/classes/IssueTagTimelineEvent.class.php. When the Timeline API retrieves tag data from the bug_history table, it may encounter tag names that no longer exist (e.g., because the tag was renamed or deleted). In this fallback path, the raw $this->tag_name value was rendered directly into the HTML output without HTML-encoding, enabling injection of arbitrary markup. The fix wraps the fallback value in a string_html_specialchars() call: changing $this->tag_name to string_html_specialchars( $this->tag_name ) (Patch Commit, GitHub Advisory). Exploitation requires low-level privileges (sufficient to create or rename tags) and passive user interaction (a victim viewing the Timeline page).
Successful exploitation allows an attacker to inject malicious HTML and, where CSP does not block inline scripts, execute arbitrary JavaScript in the context of a victim user's browser session. Potential consequences include session hijacking, credential theft, and unauthorized actions performed on behalf of the victim within the MantisBT application. The vulnerability affects the confidentiality and integrity of the vulnerable system; availability is not directly impacted (GitHub Advisory, MantisBT Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.046% (15th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.
<img src=x onerror=alert(document.cookie)>.bug_history table.tag_get_by_name() in IssueTagTimelineEvent::html() to return false, forcing the code to fall back to displaying the raw stored tag name from history.my_view_page.php). When the page renders, the unescaped tag name is injected into the HTML, executing the JavaScript payload in the victim's browser if CSP permits.my_view_page.php from unusual IP addresses or at unusual times, particularly correlated with tag rename/delete events in the MantisBT audit log.bug_history table where the tag name field contains HTML special characters (<, >, ", ') or JavaScript keywords (e.g., script, onerror, alert, document.cookie).Upgrade MantisBT to version 2.28.2 (patched), which applies the fix in commit f32787c that wraps $this->tag_name in string_html_specialchars() within IssueTagTimelineEvent::html() (GitHub Advisory, Patch Commit). If immediate upgrade is not possible, two workarounds are available: (1) manually edit offending bug_history table entries using SQL to remove or sanitize malicious tag name values; and (2) apply the one-line code fix directly by wrapping $this->tag_name in string_html_specialchars() in core/classes/IssueTagTimelineEvent.class.php. Additionally, strengthening the application's Content Security Policy (CSP) to block inline script execution will reduce the risk of JavaScript execution even if HTML injection occurs.
The vulnerability was responsibly disclosed by security researcher Vishal Shukla (GitHub: shukla304) and credited in the official MantisBT advisory. The MantisBT maintainer dregad handled remediation and published the advisory on March 23, 2026 (MantisBT Advisory). No significant broader media coverage or notable community commentary beyond the official advisory and standard vulnerability database entries has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."