XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18883.json"