Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter (CVE-2026-18387) | HOL Guard CVE