In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
mitre·CWE-116·Published 2018-08-18