CVE-2026-46594: PHP Jabbers PHP Poll Script
Medium severity, CVSS 5.1. EPSS: 0.6% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1.
Affected products
- PHP Jabbers PHP Poll Script: before 4.1 (fixed in 4.1)
Published 2026-07-31. Last modified 2026-08-28.