ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close (CVE-2026-63670) | HOL Guard CVE