VYPR

Vendor CVEs

Phpjabbers

All CVEs

152 total · sorted by risk
  • CVE-2023-48834HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48833HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48831HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

  • CVE-2023-36127HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-43274HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.

  • CVE-2023-41539HigAug 30, 2023
    risk 0.49cvss 7.5epss 0.01

    phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.

  • CVE-2023-38830HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.

  • CVE-2023-36135HigAug 4, 2023
    risk 0.49cvss 7.5epss 0.01

    User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-53878MedDec 15, 2025
    risk 0.45cvss epss 0.00

    Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass…

  • CVE-2020-35416MedDec 15, 2020
    risk 0.43cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2023-51295MedMay 8, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

  • CVE-2023-51339MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2023-51335MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

  • CVE-2023-51331MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.01

    PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2023-51327MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2023-51326MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2023-51324MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2023-51323MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2023-51321MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2023-51317MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

  • CVE-2023-51297MedFeb 19, 2025
    risk 0.42cvss 6.5epss 0.01

    A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2023-36136MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.

  • CVE-2023-51308MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

  • CVE-2023-51303MedFeb 19, 2025
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

  • CVE-2023-51300MedFeb 19, 2025
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

  • CVE-2023-51299MedFeb 19, 2025
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

  • CVE-2023-51296MedFeb 19, 2025
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code

  • CVE-2024-57427MedFeb 6, 2025
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct…

  • CVE-2023-48208MedDec 7, 2023
    risk 0.40cvss 6.1epss 0.01

    A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.

  • CVE-2023-36126MedOct 10, 2023
    risk 0.40cvss 6.1epss 0.00

    There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0

  • CVE-2023-41538MedAug 30, 2023
    risk 0.40cvss 6.1epss 0.01

    phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.

  • CVE-2023-41537MedAug 30, 2023
    risk 0.40cvss 6.1epss 0.00

    phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.

  • CVE-2023-40755MedAug 28, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

  • CVE-2023-40752MedAug 28, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

  • CVE-2023-40751MedAug 28, 2023
    risk 0.40cvss 6.1epss 0.01

    PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.

  • CVE-2023-40750MedAug 28, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.

  • CVE-2023-36315MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.00

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0.

  • CVE-2023-36314MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.00

    There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0.

  • CVE-2023-36313MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed".

  • CVE-2023-36310MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.00

    There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

  • CVE-2023-36309MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.00

    There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.

  • CVE-2023-36138MedAug 4, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.

  • CVE-2023-36137MedAug 4, 2023
    risk 0.40cvss 6.1epss 0.00

    There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.

  • CVE-2023-34869MedAug 1, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php?controller=pjAdmin&action=pjActionForgot.

  • CVE-2023-33564MedAug 1, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.

  • CVE-2023-33560MedAug 1, 2023
    risk 0.40cvss 6.1epss 0.01

    There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.

  • CVE-2020-22224MedNov 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionPreview function.

  • CVE-2020-22222MedNov 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionLoadCss function.

  • CVE-2017-12813MedDec 30, 2017
    risk 0.40cvss 6.1epss 0.01

    PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.

  • CVE-2017-12812MedDec 30, 2017
    risk 0.40cvss 6.1epss 0.01

    PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.