Phpjabbers
phpjabbers
139 CVEs • 37 products
Products (37)
Click to collapseToggle
Products (37)
Click to collapse
CVEs (139)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. |
1Phpjabbers 1Event Booking Calendar Jun 17, 2026 Feb 19, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labe...Show more |
A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) v...Show more |
1Phpjabbers 1Event Booking Calendar Jun 17, 2026 Feb 19, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitr...Show more |
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Deni...Show more |
1Phpjabbers 1Cinema Booking System Jun 17, 2026 Feb 6, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthori...Show more |
A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting...Show more |
1Phpjabbers 1Cinema Booking System Jun 17, 2026 Feb 6, 2025 N/A· v4 9.3 CRITICAL· v3 N/A· v2 A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjA...Show more |
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can cra...Show more |
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion. |
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. |
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code. |
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. |
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. |
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. |
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion. |
1Phpjabbers 1Time Slots Booking Calendar Jun 17, 2026 Dec 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. |
1Phpjabbers 1Availability Booking Calendar Jun 17, 2026 Dec 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. |
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. |