MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs (CVE-2026-86440) | HOL Guard CVE