phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
https://github.com/phpipam/phpipam/issues/3351
https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2021-35438.md