Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator precedence (CVE-2026-52730) | HOL Guard CVE