Pagure prior to 5.6 allows XSS via the templates/blame.html blame view.
redhat pagure
opensuse leap 15.1
opensuse backports sle 15.0