CVE-2026-1700

LOW

projectworlds House Rental and Property Listing 1.0 - Cross-Site Scripting via SMS Message Parameter

Title source: llm
STIX 2.1

Description

A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.343490
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.343490
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.741977
Exploit, Issue Tracking, Mitigation, Third Party Advisory exploit issue-tracking
https://github.com/jiahao412/CVE/issues/3

Scores

CVSS v3 3.5
EPSS 0.0001
EPSS Percentile 2.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
projectworlds/house_rental_and_property_listing_project 1.0
Published Jan 30, 2026
Tracked Since Feb 18, 2026