Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameter (CVE-2026-17089) | HOL Guard CVE