Kiwi TCMS vulnerable to stored XSS via JavaScript: URI in extra_link field (TestPlan & TestCase) (CVE-2026-55630) | HOL Guard CVE