FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact Form Fields (CVE-2026-56785) | HOL Guard CVE