Shaarli vulnerable to stored XSS via raw bookmark title in document <title> element on public permalink page (CVE-2026-50190) | HOL Guard CVE