Apache Roller: Stored cross-site scripting through incoming Trackback links (CVE-2026-82546) | HOL Guard CVE