TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments (CVE-2026-47762) | HOL Guard CVE