OX App Suite up to and including 7.10.4 allows XSS via an inline image with a crafted filename.
open-xchange open-xchange appsuite