kkFileView 4.0.0 contains multiple cross-site scripting vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.
View the template here CVE-2022-29349.yaml
References:
https://github.com/ARPSyndicate/cvemon