Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Parameter (CVE-2026-12936) | HOL Guard CVE