NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Parameter (CVE-2026-15602) | HOL Guard CVE