openITCOCKPIT prior to 3.7.1 has reflected XSS in the 404-not-found component.
it-novum openitcockpit