GeoNetwork has reflected XSS through client-side template injection (CVE-2026-39379) | HOL Guard CVE