CVE-2018-19918
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.
Date published : 2018-12-31
https://github.com/CuppaCMS/CuppaCMS/issues/3
https://github.com/security-breachlock/CVE-2018-19918/blob/master/cuppa_svg.pdf