DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-19915.json"