PatchSiren

mahmoudai1 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM mahmoudai1 CVE published 2026-04-28

CVE-2026-37750

CVE-2026-37750 is a reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1. The vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php. The CVSS score is 6.1, indicating a medium severity. This vulnerability has been publicly disclosed and may be actively exploited. [truncated]