Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to AjaxSearch.
https://exchange.xforce.ibmcloud.com/vulnerabilities/57635
http://secunia.com/advisories/39298
http://modxcms.com/forums/index.php/topic%2C47759.msg280304.html#msg280304