In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14765.json"