Orangescrum version 1.8.0 suffers from reflective and persistent cross site scripting vulnerabilities.