ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Parameter Name (CVE-2026-92554) | HOL Guard CVE