CVE-2026-73052: siyuan-note siyuan: SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option… | Rapid7 Vulnerability Database