MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting (CVE-2026-13005) | HOL Guard CVE