CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System (CVE-2026-54644) | HOL Guard CVE