Erxes before 0.23.0 contains a cross-site scripting vulnerability. The value of topicID parameter is not escaped and is triggered in the enclosing script tag.
id: CVE-2021-32853
info:
name: Erxes <0.23.0 - Cross-Site Scripting
author: dwisiswant0
sever
...