XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter.
- https://packetstormsecurity.com/files/146855/Domaintrader-2.5.3-Cross-Site-Scripting.html
- https://github.com/ashangp923/CVE-2018-10097