The beesblog (aka Bees Blog) component before 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.php sharing_url is mishandled.
https://zigrin.com/advisories/thirty-bees-reflected-cross-site-scripting-vulnerability/
https://github.com/thirtybees/beesblog/compare/1.6.1...1.6.2
https://github.com/thirtybees/beesblog/commit/a3aeed8fcf01c8e4112c168cf2ef7d67c8056daf