Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String (CVE-2026-88897) | HOL Guard CVE