Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover (CVE-2026-46396) | HOL Guard CVE