The beesblog (aka Bees Blog) component prior to 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.php sharing_url is mishandled.
thirtybees bees blog