YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) (CVE-2026-52772) | HOL Guard CVE