Various rawParams() and escaped() updates to prevent XSS in Wikibase extension (CVE-2026-103439) | HOL Guard CVE