In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7543.json"