A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php.
https://github.com/menevarad007/CVE-2026-37750
https://github.com/mahmoudai1/school-management-system/blob/main/register.php