phpMyFAQ has Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() Sanitization (CVE-2026-46363) | HOL Guard CVE