MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type List (CVE-2026-95661) | HOL Guard CVE