Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions (CVE-2026-63459) | HOL Guard CVE