CVE-2026-86238

A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

  • Published Sep 7, 2026
  • CVSS 2.1 low
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86238 at the National Vulnerability Database