MonoX up to and including 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
mono monox