YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters (CVE-2026-52770) | HOL Guard CVE