Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter (CVE-2026-15948) | HOL Guard CVE