A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).
https://github.com/sromanhu/ConcreteCMS-Stored-XSS---Site_Installation
https://documentation.concretecms.org/developers/introduction/version-history/923-release-notes