MantisBT 2.28.1 Released

Security release addressing:

  • A critical vulnerability affecting the SOAP API on MySQL (CVE-2026-30849); details will be disclosed at a later time;
  • Two HTML injection / XSS issues with tag names (CVE not yet assigned).

Many thanks to Alexander Philiotis of SynerComm and Vishal Shukla for discovering and responsibly reporting the issues.

A few regression issues introduced in 2.28.0 have been fixed as well. Please refer to the Change Log for complete details.

All installations are advised to upgrade as soon as possible.

Go ahead and download the release from our website.

In order to stay up to date with the latest MantisBT news, please star our GitHub repository, join our Gitter channel, or follow us on X or Mastodon and retweet to spread the word!

Critical Security Issue in MantisBT <= 2.28.0

A critical vulnerability (CVE-2026-30849) has been identified in MantisBT 2.28.0 and earlier releases, affecting instances running on MySQL and compatible databases.

MantisBT 2.28.1 includes a fix addressing the issue and will be available on Monday, March 16th 2026, around 12:00 UTC. Be ready to patch your system right away ! All installations are advised to upgrade as quickly as possible.

Considering the issue’s nature and high severity, we decided to publish this advance notice to inform administrators so they can plan ahead and patch their systems before complete details about the issue become available to the general public, in the hope that exposed systems are updated before the vulnerability can be exploited. Full disclosure will take place on March 23rd.

We would like to thank to Alexander Philiotis of SynerComm for discovering and responsibly reporting the issue.

MantisBT 2.28.0 Released

This long-awaited release includes nearly 80 enhancements and bug fixes. Here are a few highlights among the many changes, please refer to the Change Log for complete details.

  • Compatibility with PHP 8.4 and 8.5
  • Improved documentation, including an OpenAPI Description for the REST API.
  • Better Tags management
  • Restored included pages functionality (top/bottom_include_page options and triggering of EVENT_LAYOUT_PAGE_HEADER)

Special thanks to Nikolay Raspopov for his significant contribution to this release.

All installations are advised to upgrade as soon as possible.

Go ahead and download the release from our website.

In order to stay up to date with the latest MantisBT news, please star our GitHub repository, join our Gitter channel, or follow us on X or Mastodon and retweet to spread the word!

MantisBT 2.27.3 Released

Hotfix release addressing a couple of regression issues affecting Admin Checks introduced by 2.27.2. Please refer to the Change Log for details.

All installations are advised to upgrade as soon as possible.

Go ahead and download the release from our website.

In order to stay up to date with the latest MantisBT news, please star our GitHub repository, join our Gitter channel, or follow us on X or Mastodon and retweet to spread the word!

MantisBT 2.27.2 Released

Go ahead and download the release from our website.

In order to stay up to date with the latest MantisBT news, please star our GitHub repository, join our Gitter channel, or follow us on X or Mastodon and retweet to spread the word!

Note that MantisBT 2.27 is only compatible with PHP up to version 8.3. Upcoming 2.28.0 release will bring support for PHP 8.4 and later.

MantisBT 2.27.2

Maintenance and security release addressing 4 vulnerabilities:

It also includes a score of other bug fixes and improvements. Please refer to the Change Log for details.

All installations are advised to upgrade as soon as possible.