iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings (CVE-2026-88825) | HOL Guard CVE