Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

228 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.55%—Phpjabbers Hotel Booking System19/2/202517/6/2026
A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
ModificadaMedia (6.1)0.46%—Phpjabbers Event Booking Calendar19/2/202517/6/2026
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code
ModificadaAlta (7.5)0.75%—Phpjabbers Event Booking Calendar19/2/202517/6/2026
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
AnalizadaCrítica (9.8)0.88%💥 PoCPhpjabbers Cinema Booking System6/2/202517/6/2026
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
AnalizadaMedia (5.4)0.28%💥 PoCPhpjabbers Cinema Booking System6/2/202517/6/2026
A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.
AnalizadaCrítica (9.3)0.76%💥 PoCPhpjabbers Cinema Booking System6/2/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection,…
AnalizadaMedia (6.1)0.45%💥 PoCPhpjabbers Cinema Booking System6/2/202517/6/2026
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.
ModificadaAlta (8.8)1.2%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
ModificadaAlta (7.5)1.1%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
ModificadaMedia (5.4)0.42%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaMedia (5.4)0.46%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
ModificadaMedia (5.4)0.46%—Phpjabbers CAR Rental Script7/12/202317/6/2026
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
ModificadaMedia (5.4)0.46%—Phpjabbers CAR Rental Script7/12/202317/6/2026
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaAlta (8.8)1.2%—Phpjabbers CAR Rental Script7/12/202317/6/2026
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
ModificadaAlta (7.5)1.1%—Phpjabbers CAR Rental Script7/12/202317/6/2026
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
ModificadaAlta (7.5)1.1%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
ModificadaAlta (7.5)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
ModificadaAlta (8.8)1.2%—Phpjabbers Shuttle Booking Software7/12/202317/6/2026
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaAlta (8.8)1.2%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
ModificadaMedia (5.4)0.45%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
ModificadaMedia (6.1)0.50%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
ModificadaAlta (8.8)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
ModificadaMedia (5.4)0.72%—Phpjabbers Shuttle Booking Software7/12/202317/6/2026
A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
Orbitaley — Vulnerabilidades