xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS (CVE-2026-61784) | HOL Guard CVE