Skip to main content

Vendor archive

phpjabbers CVEs

Beta · best-effort

139 CVEs tagged to vendor phpjabbers30 Critical, 29 High, 78 Medium, 2 Low, 0 Unrated.

CVE-2023-51317

Published Feb 20, 2025

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" par…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51316

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, lea…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51315

Published Feb 20, 2025

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name"…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51314

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51313

Published Feb 20, 2025

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficien…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51311

Published Feb 20, 2025

PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51310

Published Feb 20, 2025

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a l…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51309

Published Feb 20, 2025

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, lea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51308

Published Feb 20, 2025

PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" param…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51303

Published Feb 19, 2025

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" p…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51302

Published Feb 19, 2025

PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient inp…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51301

Published Feb 19, 2025

A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51300

Published Feb 19, 2025

PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_k…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51299

Published Feb 19, 2025

PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51298

Published Feb 19, 2025

PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient i…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51297

Published Feb 19, 2025

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leadin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51296

Published Feb 19, 2025

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51293

Published Feb 19, 2025

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a le…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-57430

Published Feb 6, 2025

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. E…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-57429

Published Feb 6, 2025

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by trickin…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-57428

Published Feb 6, 2025

A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat nu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-57427

Published Feb 6, 2025

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 139 CVEsPage 2 of 6