Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgmcoderedeem POST Parameter in user-code-redemption.php, the ulgmuserfirst POST Parameter in user-registration-form.php, the ulgmuserlast POST Parameter in user-registration-form.php, the ulgmuseremail POST Parameter in user-registration-form.php, the ulgmcoderegistration POST Parameter in user-registration-form.php, the ulgmtermsconditions POST Parameter in user-registration-form.php, the ulgmtotalseats POST Parameter in frontend-uogroupsbuycourses.php, the uncannygroupsignupuserfirst POST Parameter in group-registration-form.php, the uncannygroupsignupuserlast POST Parameter in group-registration-form.php, the uncannygroupsignupuserlogin POST Parameter in group-registration-form.php, the uncannygroupsignupuseremail POST Parameter in group-registration-form.php, the success-invited GET Parameter in frontend-uogroups.php, the bulk-errors GET Parameter in frontend-uogroups.php, or the message GET Parameter in frontend-uogroups.php.