GutenKit <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss' (CVE-2026-2573) | HOL Guard CVE