DomainMOD through version 4.11.01 is vulnerable to cross-site scripting via the /assets/add/category.php CatagoryName and StakeHolder parameters.
View the template here CVE-2018-20011.yaml
References:
https://github.com/ARPSyndicate/kenzer-templates