YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes (CVE-2026-52774) | HOL Guard CVE