Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
{ "ubuntu_priority": "medium" }