AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks. (CVE-2022-46391)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2022-0461.json"