Photo Gallery by Ays <= 6.8.2 - Authenticated (Administrator+) SQL Injection via 's' Parameter (CVE-2026-76006) | HOL Guard CVE