OpenCATS up to and including 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
opencats opencats