GHSA-xhq9-whgq-49j5: Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions | AI Sec Watch