An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field.
- https://hackerone.com/reports/1102042
No PoCs found on GitHub currently.