MEDIUM5.4npmGHSA-25fq-6qgg-qpj8· CVE-2026-25581SCEditor has DOM XSS via emoticon URL/HTML injectionModified: 2/6/2026