Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11627.json"