YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`) (CVE-2026-52771) | HOL Guard CVE