Sitecore CMS contains a cross-site scripting vulnerability via the "special way" of displaying XML Controls directly, which allows for a Cross Site Scripting Attack.
id: CVE-2014-100004
info:
name: Sitecore CMS - Cross-Site Scripting
author: DhiyaneshDK
sever
...