Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block (CVE-2026-81918) | HOL Guard CVE