In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).