phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields (CVE-2026-46359) | HOL Guard CVE