Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG (CVE-2026-90561) | HOL Guard CVE