iRedAdmin before 2.6 allows XSS, e.g., via order_name.
https://github.com/iredmail/iRedAdmin/compare/2.5...2.6
https://github.com/iredmail/iRedAdmin/commit/b537e71ecf522d7f10180f5f0aab4a98a881893a
https://github.com/iredmail/iRedAdmin/commit/3c72b438d412ea3ee0270f6956e19b1098c19191