Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19933.json"