Vulnerability index

Browse CVEs

135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Restaurant Booking System MEDIUM 5.4
CVE-2023-51315

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_s…

No fix yet
Fix from $1,600 2025-02-20
Car Park Booking System MEDIUM 6.1
CVE-2023-51308

PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, pl…

No fix yet
Fix from $1,600 2025-02-20
Event Ticketing System MEDIUM 5.4
CVE-2023-51306

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters.

No fix yet
Fix from $1,600 2025-02-20
Event Ticketing System MEDIUM 6.1
CVE-2023-51303

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title…

No fix yet
Fix from $1,600 2025-02-19
Hotel Booking System HIGH 8.8
CVE-2023-51302

PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability …

No fix yet
Fix from $1,950 2025-02-19
Hotel Booking System HIGH 7.5
CVE-2023-51301

A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive am…

No fix yet
Fix from $1,950 2025-02-19
Hotel Booking System MEDIUM 6.1
CVE-2023-51300

PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country…

No fix yet
Fix from $1,600 2025-02-19
Hotel Booking System MEDIUM 6.1
CVE-2023-51299

PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api…

No fix yet
Fix from $1,600 2025-02-19
Hotel Booking System MEDIUM 6.5
CVE-2023-51297

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email…

No fix yet
Fix from $1,600 2025-02-19
Event Booking Calendar HIGH 7.5
CVE-2023-51293

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an exce…

No fix yet
Fix from $1,950 2025-02-19
Event Booking Calendar MEDIUM 6.1
CVE-2023-51296

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, …

No fix yet
Fix from $1,600 2025-02-19
Cinema Booking System CRITICAL 9.8
CVE-2024-57430

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queri…

No fix yet
Fix from $2,300 2025-02-06
Cinema Booking System CRITICAL 9.3
CVE-2024-57428

A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (eve…

No fix yet
Fix from $2,300 2025-02-06
Cinema Booking System MEDIUM 6.1
CVE-2024-57427

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowin…

No fix yet
Fix from $1,600 2025-02-06
Cinema Booking System MEDIUM 5.4
CVE-2024-57429

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to …

No fix yet
Fix from $1,600 2025-02-06
Appointment Scheduler HIGH 8.8
CVE-2023-48841

Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

No fix yet
Fix from $1,950 2023-12-07
Appointment Scheduler HIGH 7.5
CVE-2023-48840

A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Car Rental Script MEDIUM 5.4
CVE-2023-48837

Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

No fix yet
Fix from $1,600 2023-12-07
Appointment Scheduler MEDIUM 5.4
CVE-2023-48838

Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.

No fix yet
Fix from $1,600 2023-12-07
Appointment Scheduler MEDIUM 5.4
CVE-2023-48839

Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_cod…

No fix yet
Fix from $1,600 2023-12-07
Shuttle Booking Software HIGH 8.8
CVE-2023-48830

Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.

No fix yet
Fix from $1,950 2023-12-07
Car Rental Script HIGH 8.8
CVE-2023-48835

Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

No fix yet
Fix from $1,950 2023-12-07
Availability Booking Calendar HIGH 7.5
CVE-2023-48831

A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Time Slots Booking Calendar HIGH 7.5
CVE-2023-48833

A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Car Rental Script HIGH 7.5
CVE-2023-48834

A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Car Rental Script MEDIUM 5.4
CVE-2023-48836

Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, c…

No fix yet
Fix from $1,600 2023-12-07
Time Slots Booking Calendar HIGH 8.8
CVE-2023-48826

Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.

No fix yet
Fix from $1,950 2023-12-07
Availability Booking Calendar MEDIUM 5.4
CVE-2023-48825

Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

No fix yet
Fix from $1,600 2023-12-07
Time Slots Booking Calendar MEDIUM 5.4
CVE-2023-48827

Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_i…

No fix yet
Fix from $1,600 2023-12-07
Time Slots Booking Calendar MEDIUM 5.4
CVE-2023-48828

Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_count…

No fix yet
Fix from $1,600 2023-12-07