Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer (CVE-2026-61607) | HOL Guard CVE