admin/index.php in Monstra CMS 3.0.4 allows XSS via the pagemetatitle parameter in an add_page action.