CVE-2026-0730
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
08/01/2026
Last modified:
22/01/2026
Description
A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
2.40
Severity 3.x
LOW
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:phpgurukul:staff_leave_management_system:1.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



