Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki (CVE-2026-52774) | HOL Guard CVE