Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
- https://www.tenable.com/security/research/tra-2018-37
No PoCs found on GitHub currently.