CVE-2016-7111: Mantisbt

Medium severity, CVSS 4.7. EPSS: 1% chance of exploitation in the next 30 days.

MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

Affected products

  • Mantisbt Mantisbt: up to and including 1.3.0; version 2.0.0 only

Published 2017-02-17. Last modified 2026-06-17.