October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7198.json"