CVE-2026-39960: MantisBT is Vulnerable to Stored XSS in Custom Field Textarea Values
(updated )
Improper escaping of a textarea custom field’s contents in the Update Issue page (bug_update_page.php) allows an attacker to inject HTML and, if CSP settings permit, execute arbitrary JavaScript when the page is loaded.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-39960 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →