๐Ÿ” CVE Alert

CVE-2026-2201

LOW 2.4

ZeroWdd studentmanager LeaveController.java addLeave cross site scripting

CVSS Score
2.4
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The code repository of the project has not been active for many years.

CWE CWE-79 CWE-94
Vendor zerowdd
Product studentmanager
Published Feb 9, 2026
Last Updated Feb 23, 2026
Stay Ahead of the Next One

Get instant alerts for zerowdd studentmanager

Be the first to know when new low vulnerabilities affecting zerowdd studentmanager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ZeroWdd / studentmanager
2151560fc0a50ec00426785ec1e01a3763b380d9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.344904 vuldb.com: https://vuldb.com/?ctiid.344904 vuldb.com: https://vuldb.com/?submit.750217 yuque.com: https://www.yuque.com/clockw1se/lts9x9/mxgrzspnzmpxu7e7

Credits

๐Ÿ” Clock12138 (VulDB User)