OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal (CVE-2026-40507) | HOL Guard CVE