PHPCMS 9.6.x up to and including 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
phpcms phpcms