CVE-2026-44657 | mantisbt Mantis Bug Tracker up to 2.28.1 XHTML file_download.php file_show_inline_token HTML injection

SecurityVulns

A vulnerability labeled as problematic has been found in mantisbt Mantis Bug Tracker up to 2.28.1. This impacts the function file_show_inline_token of the file file_download.php of the component XHTML Handler. The manipulation results in HTML injection.

This vulnerability is identified as CVE-2026-44657. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More