phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion (CVE-2026-56738) | HOL Guard CVE