CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
Published May 28, 2020.
Cmsmadesimple CMS Made Simple