Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 27 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xeroneit
Xeroneit library Management System |
|
| Vendors & Products |
Xeroneit
Xeroneit library Management System |
Mon, 26 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature that allows administrators to inject malicious scripts. Attackers can insert a payload in the Category Name field to execute arbitrary JavaScript code when the page is loaded. | |
| Title | Xeroneit Library Management System 3.1 - "Add Book Category " Stored XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T02:06:40.973Z
Reserved: 2026-01-26T14:18:25.794Z
Link: CVE-2020-36954
Updated: 2026-01-26T21:09:26.940Z
Status : Deferred
Published: 2026-01-26T18:16:25.957
Modified: 2026-04-15T00:35:42.020
Link: CVE-2020-36954
No data.
OpenCVE Enrichment
Updated: 2026-01-27T20:17:23Z