InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms (CVE-2026-85293) | HOL Guard CVE