OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
Source: NVD ↗ · CISA KEV Catalog ↗