Description
A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
This issue was fixed in version 4.1.
This issue was fixed in version 4.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1. | |
| Title | Reflected XSS in PHP Poll Script | |
| First Time appeared |
Php Jabbers
Php Jabbers php Poll Script |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:php_jabbers:php_poll_script:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Php Jabbers
Php Jabbers php Poll Script |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-07-31T19:51:30.479Z
Reserved: 2026-05-15T13:52:51.436Z
Link: CVE-2026-46594
Updated: 2026-07-31T19:51:25.612Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')