CVE-2026-90850

A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

  • Published Sep 15, 2026
  • CVSS 1.9 low
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90850 at the National Vulnerability Database