Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
{ "ubuntu_priority": "medium" }