Vulnerability index

Browse CVEs

135 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-51315 PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_s… Restaurant Booking System No fix yet Fix from $1,6002025-02-20 MEDIUM 6.1 CVE-2023-51308 PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, pl… Car Park Booking System No fix yet Fix from $1,6002025-02-20 MEDIUM 5.4 CVE-2023-51306 PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters. Event Ticketing System No fix yet Fix from $1,6002025-02-20 MEDIUM 6.1 CVE-2023-51303 PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title… Event Ticketing System No fix yet Fix from $1,6002025-02-19 HIGH 8.8 CVE-2023-51302 PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability … Hotel Booking System No fix yet Fix from $1,9502025-02-19 HIGH 7.5 CVE-2023-51301 A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive am… Hotel Booking System No fix yet Fix from $1,9502025-02-19 MEDIUM 6.1 CVE-2023-51300 PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country… Hotel Booking System No fix yet Fix from $1,6002025-02-19 MEDIUM 6.1 CVE-2023-51299 PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api… Hotel Booking System No fix yet Fix from $1,6002025-02-19 MEDIUM 6.5 CVE-2023-51297 A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email… Hotel Booking System No fix yet Fix from $1,6002025-02-19 HIGH 7.5 CVE-2023-51293 A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an exce… Event Booking Calendar No fix yet Fix from $1,9502025-02-19 MEDIUM 6.1 CVE-2023-51296 PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, … Event Booking Calendar No fix yet Fix from $1,6002025-02-19 CRITICAL 9.8 CVE-2024-57430 An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queri… Cinema Booking System No fix yet Fix from $2,3002025-02-06 CRITICAL 9.3 CVE-2024-57428 A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (eve… Cinema Booking System No fix yet Fix from $2,3002025-02-06 MEDIUM 6.1 CVE-2024-57427 PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowin… Cinema Booking System No fix yet Fix from $1,6002025-02-06 MEDIUM 5.4 CVE-2024-57429 A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to … Cinema Booking System No fix yet Fix from $1,6002025-02-06 HIGH 8.8 CVE-2023-48841 Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. Appointment Scheduler No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48840 A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion. Appointment Scheduler No fix yet Fix from $1,9502023-12-07 MEDIUM 5.4 CVE-2023-48837 Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. Car Rental Script No fix yet Fix from $1,6002023-12-07 MEDIUM 5.4 CVE-2023-48838 Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code. Appointment Scheduler No fix yet Fix from $1,6002023-12-07 MEDIUM 5.4 CVE-2023-48839 Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_cod… Appointment Scheduler No fix yet Fix from $1,6002023-12-07 HIGH 8.8 CVE-2023-48830 Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. Shuttle Booking Software No fix yet Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-48835 Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. Car Rental Script No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48831 A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. Availability Booking Calendar No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48833 A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. Time Slots Booking Calendar No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48834 A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion. Car Rental Script No fix yet Fix from $1,9502023-12-07 MEDIUM 5.4 CVE-2023-48836 Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, c… Car Rental Script No fix yet Fix from $1,6002023-12-07 HIGH 8.8 CVE-2023-48826 Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. Time Slots Booking Calendar No fix yet Fix from $1,9502023-12-07 MEDIUM 5.4 CVE-2023-48825 Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. Availability Booking Calendar No fix yet Fix from $1,6002023-12-07 MEDIUM 5.4 CVE-2023-48827 Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_i… Time Slots Booking Calendar No fix yet Fix from $1,6002023-12-07 MEDIUM 5.4 CVE-2023-48828 Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_count… Time Slots Booking Calendar No fix yet Fix from $1,6002023-12-07