Vendor CVEs
Phpjabbers
All CVEs
152 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-53926 | Cri | 0.64 | 9.8 | 0.01 | Dec 17, 2025 | PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or… | ||
| CVE-2023-53877 | Cri | 0.64 | 9.8 | 0.00 | Dec 15, 2025 | Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the… | ||
| CVE-2024-57430 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2025 | An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or… | ||
| CVE-2023-36140 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2023 | In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. | ||
| CVE-2023-40767 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40766 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40765 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40764 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40763 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40762 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40761 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40760 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40759 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40758 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40757 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40756 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-40749 | Cri | 0.64 | 9.8 | 0.03 | Aug 28, 2023 | PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. | ||
| CVE-2023-40748 | Cri | 0.64 | 9.8 | 0.03 | Aug 28, 2023 | PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. | ||
| CVE-2023-36311 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0. | ||
| CVE-2023-39776 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2023-36139 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2023 | In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||
| CVE-2023-36134 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||
| CVE-2023-36133 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. | ||
| CVE-2023-36132 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. | ||
| CVE-2023-36131 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. | ||
| CVE-2023-33562 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||
| CVE-2023-33561 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2023 | Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords. | ||
| CVE-2020-22226 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2021 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function. | ||
| CVE-2020-22225 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2021 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. | ||
| CVE-2020-22223 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2021 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function. | ||
| CVE-2024-57428 | Cri | 0.61 | 9.3 | 0.01 | Feb 6, 2025 | A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript,… | ||
| CVE-2023-51336 | Hig | 0.57 | 8.8 | 0.01 | Feb 20, 2025 | PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used… | ||
| CVE-2023-51333 | Hig | 0.57 | 8.8 | 0.01 | Feb 20, 2025 | PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to… | ||
| CVE-2023-51319 | Hig | 0.57 | 8.8 | 0.01 | Feb 20, 2025 | PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to… | ||
| CVE-2023-51313 | Hig | 0.57 | 8.8 | 0.01 | Feb 20, 2025 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used… | ||
| CVE-2023-51311 | Hig | 0.57 | 8.8 | 0.01 | Feb 20, 2025 | PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to… | ||
| CVE-2023-51302 | Hig | 0.57 | 8.8 | 0.01 | Feb 19, 2025 | PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to… | ||
| CVE-2023-48841 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. | ||
| CVE-2023-48835 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. | ||
| CVE-2023-48830 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. | ||
| CVE-2023-48826 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. | ||
| CVE-2023-48207 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. | ||
| CVE-2023-43147 | Hig | 0.57 | 8.8 | 0.00 | Oct 12, 2023 | PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI. | ||
| CVE-2023-40754 | Hig | 0.57 | 8.8 | 0.01 | Aug 28, 2023 | In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||
| CVE-2023-33563 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2023 | In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||
| CVE-2023-51316 | Hig | 0.49 | 7.5 | 0.01 | Feb 20, 2025 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | ||
| CVE-2023-51314 | Hig | 0.49 | 7.5 | 0.01 | Feb 20, 2025 | A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated… | ||
| CVE-2023-51301 | Hig | 0.49 | 7.5 | 0.01 | Feb 19, 2025 | A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail… | ||
| CVE-2023-51293 | Hig | 0.49 | 7.5 | 0.01 | Feb 19, 2025 | A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail… | ||
| CVE-2023-48840 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2023 | A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion. |
- risk 0.64cvss 9.8epss 0.01
PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or…
- risk 0.64cvss 9.8epss 0.00
Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the…
- risk 0.64cvss 9.8epss 0.01
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or…
- risk 0.64cvss 9.8epss 0.00
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.03
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
- risk 0.64cvss 9.8epss 0.03
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
- risk 0.64cvss 9.8epss 0.01
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
- risk 0.64cvss 9.8epss 0.01
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.00
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- risk 0.64cvss 9.8epss 0.01
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- risk 0.64cvss 9.8epss 0.01
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
- risk 0.64cvss 9.8epss 0.01
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
- risk 0.64cvss 9.8epss 0.01
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
- risk 0.64cvss 9.8epss 0.01
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
- risk 0.64cvss 9.8epss 0.01
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
- risk 0.64cvss 9.8epss 0.01
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
- risk 0.64cvss 9.8epss 0.01
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.
- risk 0.61cvss 9.3epss 0.01
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript,…
- risk 0.57cvss 8.8epss 0.01
PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…
- risk 0.57cvss 8.8epss 0.01
PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…
- risk 0.57cvss 8.8epss 0.01
PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…
- risk 0.57cvss 8.8epss 0.01
PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…
- risk 0.57cvss 8.8epss 0.01
PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…
- risk 0.57cvss 8.8epss 0.01
PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…
- risk 0.57cvss 8.8epss 0.01
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- risk 0.57cvss 8.8epss 0.01
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- risk 0.57cvss 8.8epss 0.01
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
- risk 0.57cvss 8.8epss 0.01
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
- risk 0.57cvss 8.8epss 0.01
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
- risk 0.57cvss 8.8epss 0.00
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.
- risk 0.57cvss 8.8epss 0.01
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- risk 0.57cvss 8.8epss 0.01
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- risk 0.49cvss 7.5epss 0.01
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
- risk 0.49cvss 7.5epss 0.01
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated…
- risk 0.49cvss 7.5epss 0.01
A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…
- risk 0.49cvss 7.5epss 0.01
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…
- risk 0.49cvss 7.5epss 0.01
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
Page 1 of 4