MajorDoMo contains a reflected XSS caused by unsanitized $qry parameter in command.php, letting attackers inject arbitrary JavaScript via crafted URLs, exploit requires victim to visit malicious URL.
id: CVE-2026-27176
info:
name: MajorDoMo - Cross-Site Scripting
author: DhiyaneshDk
severity:
...