grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction (CVE-2026-58493) | HOL Guard CVE