CVE-2026-40607 | mantisbt Mantis Bug Tracker up to 2.28.1 Configuration g_show_user_realname cross site scripting (GHSA-f633-865q-2mhh)
A vulnerability described as problematic has been identified in mantisbt Mantis Bug Tracker up to 2.28.1. The affected element is an unknown function of the component Configuration g_show_user_realname Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-40607. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.