Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization (CVE-2026-65841) | HOL Guard CVE