NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name (CVE-2026-73038) | HOL Guard CVE