Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+) (CVE-2026-44642) | HOL Guard CVE