VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.
vertrigoserv project vertrigoserv 2.17