Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
https://github.com/advisories/GHSA-qw4w-vq8v-2wcv
https://www.silverstripe.org/download/security-releases/CVE-2022-37430
https://www.silverstripe.org/download/security-releases/