HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft (CVE-2026-46496) | HOL Guard CVE