lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-12978.json"