CVE-2020-16266: Mantisbt

Medium severity, CVSS 5.4. EPSS: 1.2% chance of exploitation in the next 30 days.

An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CSP settings allow it).

Affected products

  • Mantisbt Mantisbt: before 2.24.2 (fixed in 2.24.2)

Published 2020-08-12. Last modified 2026-06-17.