CVE List

CVE-2026-1146

Low 3.5

A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Published January 19, 2026.

Affected software

Get alerts for Pamzey Patients Waiting Area Queue Management System

Reference links