Phpjabbers
phpjabbers
139 CVEs • 37 products
Products (37)
Click to collapseToggle
Products (37)
Click to collapse
CVEs (139)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phpjabbers 1Bus Reservation System Jun 17, 2026 Aug 3, 2023 N/A· v4 6.1 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index/picku...Show more |
1Phpjabbers 1Availability Booking Calendar Jun 17, 2026 Aug 3, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the ar...Show more |
PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php?controller=pjAdmin&action=pjActionForgot. |
1Phpjabbers 1Time Slots Booking Calendar Jun 17, 2026 Aug 1, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3. |
1Phpjabbers 1Time Slots Booking Calendar Jun 17, 2026 Aug 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. |
1Phpjabbers 1Time Slots Booking Calendar Jun 17, 2026 Aug 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, e...Show more |
1Phpjabbers 1Time Slots Booking Calendar Jun 17, 2026 Aug 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords. |
1Phpjabbers 1Time Slots Booking Calendar Jun 17, 2026 Aug 1, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3. |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function. |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionPreview function. |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function. |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionLoadCss function. |
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action. |
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. |
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and pass...Show more |
Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller. |
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting...Show more |
Cross-site request forgery (CSRF) vulnerability in PHPJabbers Vacation Rental Script allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a create action...Show more |