XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
{ "versions": [ { "introduced": "0" }, { "last_affected": "1.4.3" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20136.json"