Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description (CVE-2026-3423) | HOL Guard CVE