CVE-2020-36954: Xeroneit Library Management System

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature that allows administrators to inject malicious scripts. Attackers can insert a payload in the Category Name field to execute arbitrary JavaScript code when the page is loaded.

Affected products

  • Xeroneit Xeroneit Library Management System: up to and including 3.1

Published 2026-01-26. Last modified 2026-06-17.