paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id parameter).
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6811.json"