SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-46594

MEDIUM · CVSS 5.1 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

A reflected cross-site scripting (XSS) vulnerability exists in the PHP Jabbers - PHP Poll Script, allowing attackers to execute arbitrary JavaScript in victims' browsers through specially crafted URLs. Organizations using affected versions of this script should prioritize patching to version 4.1 to mitigate the risk of exploitation and protect user data. This vulnerability is particularly relevant for web developers and administrators managing PHP-based applications.

CVE
CVE-2026-46594
Severity
MEDIUM
CVSS
5.1
EPSS
0.35%
Java

Original NVD Description

A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1.