CVE-2026-86238: Projectworlds Online Examination System
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
- Projectworlds Online Examination System: version 1.0 only
Published 2026-09-07. Last modified 2026-09-08.