Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS (CVE-2026-52838) | HOL Guard CVE