Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote unauthenticated attacker may execute an arbitrary script on the web browser of the user.
https://sourceforge.net/projects/rephormer/
https://jvn.jp/en/jp/JVN61054671/