Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()` (CVE-2026-54002) | HOL Guard CVE