CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php (CVE-2026-54647) | HOL Guard CVE