Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.