Projectworlds · House Rental/Property Listing · CVE-2026-1700
**Name of the Vulnerable Software and Affected Versions**
projectworlds House Rental and Property Listing version 1.0
**Description**
A weakness exists in projectworlds House Rental and Property Listing 1.0, affecting unknown code within the `/app/sms.php` file. This allows for cross site scripting through manipulation of the `Message` argument. The attack can be initiated remotely, and the exploit has been publicly released.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.