In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15809.json"