org.xwiki.commons:xwiki-commons-xml's HTML sanitizer allows form elements in restricted (CVE-2023-36471) | HOL Guard CVE