Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order' Parameter (CVE-2026-13200) | HOL Guard CVE