VYPR

Vendor CVEs

Phpjabbers

All CVEs

152 total · sorted by risk
  • CVE-2023-53926CriDec 17, 2025
    risk 0.64cvss 9.8epss 0.01

    PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or…

  • CVE-2023-53877CriDec 15, 2025
    risk 0.64cvss 9.8epss 0.00

    Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the…

  • CVE-2024-57430CriFeb 6, 2025
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or…

  • CVE-2023-36140CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.00

    In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

  • CVE-2023-40767CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40766CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40765CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40764CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40763CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40762CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40761CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40760CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40759CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40758CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40757CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40756CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40749CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.03

    PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

  • CVE-2023-40748CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.03

    PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

  • CVE-2023-36311CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

  • CVE-2023-39776CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-36139CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-36134CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-36133CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.

  • CVE-2023-36132CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.

  • CVE-2023-36131CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.

  • CVE-2023-33562CriAug 1, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-33561CriAug 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.

  • CVE-2020-22226CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.

  • CVE-2020-22225CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.

  • CVE-2020-22223CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.

  • CVE-2024-57428CriFeb 6, 2025
    risk 0.61cvss 9.3epss 0.01

    A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript,…

  • CVE-2023-51336HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2023-51333HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-51319HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-51313HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2023-51311HigFeb 20, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-51302HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.01

    PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to…

  • CVE-2023-48841HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

  • CVE-2023-48835HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

  • CVE-2023-48830HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.

  • CVE-2023-48826HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.

  • CVE-2023-48207HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.

  • CVE-2023-43147HigOct 12, 2023
    risk 0.57cvss 8.8epss 0.00

    PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.

  • CVE-2023-40754HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.01

    In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-33563HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.01

    In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-51316HigFeb 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2023-51314HigFeb 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated…

  • CVE-2023-51301HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2023-51293HigFeb 19, 2025
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2023-48840HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

Page 1 of 4