Improper escaping of Tag name when deleting it in tag_delete.php allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript.
Cross-site scripting (XSS).
80990f43153167c73f11eb4b2bc7108d0c3d6b46
%1$s from $s_tag_delete_message string, for example with sed -r -i '/tag_delete_message/s/.%1\$s.//' -- lang/MantisBT hanks Vishal Shukla for discovering and responsibly reporting the issue.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-25T19:56:00Z",
"nvd_published_at": "2026-03-23T20:16:27Z",
"severity": "HIGH"
}