TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs (CVE-2026-47760) | HOL Guard CVE