OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer (CVE-2026-48081) | HOL Guard CVE