The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator.
metinfo metinfo 6.0.0