Before WordPress 4.9.5, the version string was not escaped in the getthegenerator function, and could lead to XSS in a generator tag.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10102.json"