ProjectsAndPrograms school-management-system is vulnerable to Stored CrossโSite Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or administrator) can inject malicious JavaScript that is subsequently executed in other usersโ browsers. Critically, when chained with CVEโ2025โ11661, which allows unauthenticated access to backend
Exploit
CVE-2026-47324
VulnCheck
Refer to CVE-2026-47324 NVD advisory