phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS (CVE-2026-46360) | HOL Guard CVE