Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-37429.json"