An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-18938.json"