kkFileView 4.0.0 contains multiple cross-site scripting vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.
View the template here CVE-2022-29349.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-29349.yaml
References: