FineCMS through 5.0.10 contains a cross-site scripting vulnerability in controllers/api.php via the function parameter in a c=api&m=data2 request.
View the template here CVE-2017-11629.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-11629/