NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter (CVE-2026-13040) | HOL Guard CVE