FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal (CVE-2026-53641) | HOL Guard CVE