froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL (CVE-2026-90937) | HOL Guard CVE