Reflected Cross-Site Scripting Vulnerability in PHP Poll Script by PHP Jabbers
CVE-2026-46594

5.1MEDIUM

Key Information:

Vendor
CVE Published:
31 July 2026

What is CVE-2026-46594?

A reflected cross-site scripting vulnerability exists in PHP Jabbers' PHP Poll Script, allowing attackers to execute arbitrary JavaScript in users' browsers through a specially crafted URL. This execution can lead to unauthorized actions and data exposure for affected users. The issue has been addressed in version 4.1 of the script, highlighting the need for users to update their installations to mitigate potential attacks.

Affected Version(s)

PHP Poll Script 0 < 4.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski
Robert Kruczek
.