Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import/save (CVE-2026-5394) | HOL Guard CVE