CVE-2021-3355
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.
Date published : 2021-02-24
http://packetstormsecurity.com/files/161562/LightCMS-1.3.4-Cross-Site-Scripting.html
https://gist.github.com/Peithon/1c628ded0c4fc96c6331c3cce1d0c69b