Various rawParams() and escaped() updates to prevent XSS in Wikistories extension (CVE-2026-103438) | HOL Guard CVE