MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON (CVE-2026-95665) | HOL Guard CVE