We use lock 11.27.2. The input fields in lock.js are vulnerable to reflect XSS injection.
Please update Lock.js to latest version.