The Contact page in Monica 2.19.1 allows stored XSS via the First Name field. Post navigation CVE-2021-27369 CVE-2021-27362 (wpg)