OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-44276.json"