lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
{ "urgency": "not yet assigned" }