HotelDruid 2.3.0 contains a cross-site scripting vulnerability affecting nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
View the template here CVE-2019-8937.yaml
References:
https://sourceforge.net/projects/hoteldruid/