Contao prior to 4.5.7 has XSS in the system log.
contao contao
contao contao 4.0.0
contao contao 4.1.0
contao contao 4.2.0
contao contao 4.3.0