Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kislay Kumar

#20217of 53,633
12.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-41440
6.4
2026-05-16
Codekernel · Rsi Queue Management System · CVE-2020-37240
Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing the User List page.
PT-2026-4778
6.4
2026-01-26
Xeroneit · Xeroneit Library Management System · CVE-2020-36954
**Name of the Vulnerable Software and Affected Versions** Xeroneit Library Management System version 3.1 **Description** A stored cross-site scripting issue exists in the Book Category feature. This allows administrators to inject malicious scripts by inserting a payload into the `Category Name` field, which executes arbitrary JavaScript code when the page is loaded. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.