SourceBans before 2.0 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.
View the template here CVE-2015-8349.yaml
References:
https://www.htbridge.com/advisory/HTB23273