HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI.
fat_free_crm
{ "last_known_affected_version_range": "<= 0.19.0" }