Vulnerability index

Browse CVEs

135 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Availability Booking Calendar HIGH 8.8
CVE-2023-48207

Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.

No fix yet
Fix from $1,950 2023-12-07
Availability Booking Calendar MEDIUM 6.1
CVE-2023-48208

A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, p…

No fix yet
Fix from $1,600 2023-12-07
Shuttle Booking Software MEDIUM 5.4
CVE-2023-48172

A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, t…

No fix yet
Fix from $1,600 2023-12-07
Limo Booking Software HIGH 8.8
CVE-2023-43147

PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index…

No fix yet
Fix from $1,950 2023-10-12
Appointment Scheduler HIGH 7.5
CVE-2023-36127

User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages coul…

Mitigation only
Fix from $1,950 2023-10-10
Appointment Scheduler MEDIUM 6.1
CVE-2023-36126

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0

Mitigation only
Fix from $1,600 2023-10-10
Php Shopping Cart HIGH 7.5
CVE-2023-43274

Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.

No fix yet
Fix from $1,950 2023-09-21
Cleaning Business Software CRITICAL 9.8
CVE-2023-36140

In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

Mitigation only
Fix from $2,300 2023-09-11
Business Directory Script HIGH 7.5
CVE-2023-41539

phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.

No fix yet
Fix from $1,950 2023-08-30
Php Forum Script MEDIUM 6.1
CVE-2023-41538

phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.

No fix yet
Fix from $1,600 2023-08-30
Business Directory Script MEDIUM 6.1
CVE-2023-41537

phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.

No fix yet
Fix from $1,600 2023-08-30
Callback Widget CRITICAL 9.8
CVE-2023-40756

User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow …

Mitigation only
Fix from $2,300 2023-08-28
Food Delivery Script CRITICAL 9.8
CVE-2023-40757

User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could a…

Mitigation only
Fix from $2,300 2023-08-28
Document Creator CRITICAL 9.8
CVE-2023-40758

User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow…

Mitigation only
Fix from $2,300 2023-08-28
Restaurant Booking Script CRITICAL 9.8
CVE-2023-40759

User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages c…

Mitigation only
Fix from $2,300 2023-08-28
Hotel Booking System CRITICAL 9.8
CVE-2023-40760

User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could …

Mitigation only
Fix from $2,300 2023-08-28
Yacht Listing Script CRITICAL 9.8
CVE-2023-40761

User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could a…

Mitigation only
Fix from $2,300 2023-08-28
Fundraising Script CRITICAL 9.8
CVE-2023-40762

User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could all…

Mitigation only
Fix from $2,300 2023-08-28
Taxi Booking Script CRITICAL 9.8
CVE-2023-40763

User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could al…

Mitigation only
Fix from $2,300 2023-08-28
Car Rental Script CRITICAL 9.8
CVE-2023-40764

User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could all…

Mitigation only
Fix from $2,300 2023-08-28
Event Booking Calendar CRITICAL 9.8
CVE-2023-40765

User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could…

Mitigation only
Fix from $2,300 2023-08-28
Ticket Support Script CRITICAL 9.8
CVE-2023-40766

User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages cou…

Mitigation only
Fix from $2,300 2023-08-28
Make An Offer Widget CRITICAL 9.8
CVE-2023-40767

User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages coul…

Mitigation only
Fix from $2,300 2023-08-28
Food Delivery Script CRITICAL 9.8
CVE-2023-40748

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

Mitigation only
Fix from $2,300 2023-08-28
Food Delivery Script CRITICAL 9.8
CVE-2023-40749

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

Mitigation only
Fix from $2,300 2023-08-28
Car Rental Script HIGH 8.8
CVE-2023-40754

In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attacker…

Mitigation only
Fix from $1,950 2023-08-28
Yacht Listing Script MEDIUM 6.1
CVE-2023-40750

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.

Mitigation only
Fix from $1,600 2023-08-28
Fundraising Script MEDIUM 6.1
CVE-2023-40751

PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.

Mitigation only
Fix from $1,600 2023-08-28
Make An Offer Widget MEDIUM 6.1
CVE-2023-40752

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

Mitigation only
Fix from $1,600 2023-08-28
Callback Widget MEDIUM 6.1
CVE-2023-40755

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

Mitigation only
Fix from $1,600 2023-08-28