Jeedom through 4.0.38 contains a cross-site scripting vulnerability. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
View the template here CVE-2020-9036.yaml
References:
https://github.com/my3ker/my3ker-cve-workshop