Pagure before 5.6 allows XSS via the templates/blame.html blame view.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2021-0206.json"