Recommender before 2018-07-18 allows XSS.
"https://github.com/pypa/advisory-database/blob/main/vulns/recommender-xblock/PYSEC-2019-219.yaml"