ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter (CVE-2026-3652) | HOL Guard CVE