CVE-2026-39112
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Apr 20, 2026
Vendor
unknown
Description
Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisitors.php or visitor-detail.php.