Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_description' Parameter (CVE-2026-76562) | HOL Guard CVE