Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter (CVE-2026-13754) | HOL Guard CVE