DomainMOD through version 4.11.01 is vulnerable to cross-site scripting via the /assets/add/category.php CatagoryName and StakeHolder parameters.
id: CVE-2018-20011
info:
name: DomainMOD 4.11.01 - Cross-Site Scripting
author: arafatansari
...