This script is possibly vulnerable to XPath Injection attacks.
XPath Injection is an attack technique used to exploit web sites that construct XPath queries from user-supplied input.
An unauthenticated attacker may extract a complete XML document using XPath querying. This may compromise the integrity of your database and expose sensitive information.
Your script should filter metacharacters from user input.
XPath injection in XML databases