CVE-2026-44657EPSS p45.9%
CVE-2026-44657CVE-2026-44657
Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in 2.28.2.
Scoring
| EPSS | 0.58% probability of exploitation · percentile 45.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-21 |