Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the subject in a post, or the user parameter to (2) profile.php and (3) mail.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.026
EPSS Ranking 85.2%