PHP-Nuke 7.4 has a cross site scripting flaw that allows an attacker the ability to post global homepage messages.