libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-27920.json"