Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order_by' Parameter (CVE-2026-13191) | HOL Guard CVE