CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.