White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings (CVE-2026-11898) | HOL Guard CVE