LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoint (CVE-2026-63360) | HOL Guard CVE