An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in managepluginpage.php and managepluginuninstall.php when a crafted plugin is installed.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-26144.json"