Skip to main content

Vendor archive

phpjabbers CVEs

Beta · best-effort

139 CVEs tagged to vendor phpjabbers30 Critical, 29 High, 78 Medium, 2 Low, 0 Unrated.

CVE-2023-53927

Published Dec 17, 2025

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Att…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53926

Published Dec 17, 2025

PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafte…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-53877

Published Dec 15, 2025

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-ba…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-10827

Published Sep 23, 2025

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of t…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-51295

Published May 8, 2025

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parame…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51339

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, lea…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51338

Published Feb 20, 2025

PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters of index.php page.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51336

Published Feb 20, 2025

PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insuffici…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51334

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, lead…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51333

Published Feb 20, 2025

PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51332

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51331

Published Feb 20, 2025

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficie…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51327

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51326

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51324

Published Feb 20, 2025

PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insuffici…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51323

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51321

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51320

Published Feb 20, 2025

PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insuffici…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51319

Published Feb 20, 2025

PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient i…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 139 CVEsPage 1 of 6