Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter (CVE-2026-17037) | HOL Guard CVE