SunEditor: DOM XSS in SunEditor Embed Plugin via External Script Element After Iframe Embed (CVE-2026-54606) | HOL Guard CVE