CVE-2026-89268: Webkul QloApps: QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping… | Rapid7 Vulnerability Database