Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value (CVE-2026-18666) | HOL Guard CVE