CVE-2026-25773: Focalboard Second-Order SQL Injection in category reorder endpoint allows data exfiltration (unsupported product, no fix) — Zero Day Monitor