Paymenter has URL parameter injection that bypasses paid plan limits at checkout (CVE-2026-47198) | HOL Guard CVE