CVE-2026-49048: JoomCCK SQL Injection via Unescaped Parameter Concatenation — Casky — Casky