Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem.
kentico kentico cms 13.0.44