MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php (CVE-2026-49273) | HOL Guard CVE