MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page (CVE-2026-40598) | HOL Guard CVE