The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
monicahq monica 2.19.1