The "Count per Day" plugin prior to 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
count per day project count per day