Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor (CVE-2026-72730) | HOL Guard CVE