The Neon theme 2.0 prior to 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
laborator neon