← Back

Phpjabbers

phpjabbers

139 CVEs • 37 products

Products (37)

Click to collapse
Toggle
Simple Cms
simple_cms
Rate Me
rate_me

CVEs (139)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpjabbers
1Hotel Booking System
Jun 17, 2026
Feb 19, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
1Phpjabbers
1Event Booking Calendar
Jun 17, 2026
Feb 19, 2025
N/A· v4
4.7 MEDIUM· v3
N/A· v2
PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labe...Show more
PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.Show less
1Phpjabbers
1Hotel Booking System
Jun 17, 2026
Feb 19, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) v...Show more
A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.Show less
1Phpjabbers
1Event Booking Calendar
Jun 17, 2026
Feb 19, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitr...Show more
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary codeShow less
1Phpjabbers
1Event Booking Calendar
Jun 17, 2026
Feb 19, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Deni...Show more
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.Show less
1Phpjabbers
1Cinema Booking System
Jun 17, 2026
Feb 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthori...Show more
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.Show less
1Phpjabbers
1Cinema Booking System
Jun 17, 2026
Feb 6, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting...Show more
A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.Show less
1Phpjabbers
1Cinema Booking System
Jun 17, 2026
Feb 6, 2025
N/A· v4
9.3 CRITICAL· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjA...Show more
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.Show less
1Phpjabbers
1Cinema Booking System
Jun 17, 2026
Feb 6, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can cra...Show more
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.Show less
1Phpjabbers
1Appointment Scheduler
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
1Phpjabbers
1Appointment Scheduler
Jun 17, 2026
Dec 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
1Phpjabbers
1Appointment Scheduler
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
1Phpjabbers
1Appointment Scheduler
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
1Phpjabbers
1Car Rental Script
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
1Phpjabbers
1Car Rental Script
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
1Phpjabbers
1Car Rental Script
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
1Phpjabbers
1Car Rental Script
Jun 17, 2026
Dec 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
1Phpjabbers
1Time Slots Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
1Phpjabbers
1Availability Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
1Phpjabbers
1Shuttle Booking Software
Jun 17, 2026
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.