Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options (CVE-2026-86841) | HOL Guard CVE