CVE-2006-1913: Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attacke
infovulnerability
security
Summary
A cross-site scripting vulnerability (XSS, a type of attack where an attacker injects malicious code into a webpage that runs in other users' browsers) exists in Jax Guestbook versions 3.1, 3.31, and 3.50 in the jax_guestbook.php file. Remote attackers can exploit this by injecting arbitrary web script or HTML through the page parameter. The vulnerability has a CVSS 4.0 severity rating (a 0-10 scale measuring how serious a security flaw is).
Vulnerability Details
CVSS Score
6.8
EPSS (30-day exploit probability)
EPSS: 1.4%
Classification
Attack SophisticationTrivial
Original source: https://nvd.nist.gov/vuln/detail/CVE-2006-1913
First tracked: February 15, 2026 at 08:42 PM
Classified by LLM (prompt v3) · confidence: 95%