QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters (CVE-2026-15984) | HOL Guard CVE