CiviCRM could be made to run malicious JavaScript in the user's browser if it received specially crafted input.

Source: Ubuntu 22.04 CiviCRM Important JavaScript Execution Risk USN-8242-1