Mantis Bug Tracker (MantisBT) fixed two high-severity vulnerabilities in version 2.28.1, including an authentication bypass in the SOAP API tracked as CVE-2026-30849. On MySQL-family databases, improper type checking of the password parameter lets an attacker who knows a victim's username authenticate without the real password by sending a crafted SOAP request, then invoke any SOAP API function available to that account. The issue is specific to MySQL-related implicit string-to-integer conversion behavior; other supported database backends are not affected in the same way. Disabling the SOAP API can reduce risk, but advisories note that some user account information such as email addresses and real names may still remain exposed.
MantisBT 2.28.0 also contains a stored HTML injection flaw, CVE-2026-33548, in the Timeline view on my_view_page.php. The bug stems from improper escaping of tag names pulled from History, allowing HTML injection—and potentially arbitrary JavaScript execution if Content Security Policy settings permit—when renamed or deleted tags are displayed. The vendor addressed the issue in 2.28.1 and published workarounds that include cleaning affected History entries in SQL and updating code to use string_html_specialchars() in IssueTagTimelineEvent::html(). Together, the flaws expose MantisBT deployments to account compromise through the API and client-side code execution in the web interface.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A public advisory disclosed CVE-2026-33517, a stored HTML injection/XSS flaw in MantisBT 2.28.0's tag_delete.php deletion confirmation message that could allow authenticated attackers to inject HTML or JavaScript. The issue was fixed in MantisBT 2.28.1, with workarounds including reverting a related commit or removing the %1$s placeholder from the tag deletion message string.
Public advisories dated March 23, 2026 disclosed details for CVE-2026-33548 and CVE-2026-30849, including affected versions, impact, and available mitigations or workarounds.
GitHub Security Advisories newly received CVE-2026-33548 on March 23, 2026, documenting the stored HTML injection/XSS vulnerability in MantisBT Timeline tag handling.
MantisBT addressed both vulnerabilities in version 2.28.1, fixing improper escaping of tag names in Timeline view and the SOAP API password type-checking issue on MySQL-family databases.
Mantis Bug Tracker version 2.28.0 was affected by two vulnerabilities: a stored HTML injection/XSS issue in Timeline tag display and a SOAP API authentication bypass affecting MySQL-family deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.