Craft CMS before 2.6.2974 allows XSS attacks.
{ "cwe_ids": [ "CWE-79" ], "github_reviewed": true, "github_reviewed_at": "2023-07-27T22:27:30Z", "severity": "MODERATE", "nvd_published_at": "2017-04-22T01:59:00Z" }
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xv5f-2997-qhrq/GHSA-xv5f-2997-qhrq.json"