Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

228 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.21%—Process-one EjabberdAI2/10/20262/10/2026
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
AplazadaMedia (5.1)0.55%—Phpjabbers PHP Poll ScriptAI31/7/202628/8/2026
A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1.
AplazadaAlta (8.6)0.38%—Phpjabbers PHP Poll ScriptAI31/7/202628/8/2026
A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.
AplazadaMedia (6.9)0.22%—Phpjabbers PHP JabbersAI31/7/202629/9/2026
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating…
AplazadaAlta (8.6)0.38%—Phpjabbers PHP JabbersAI31/7/202629/9/2026
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in…
AplazadaCrítica (9.3)0.44%—Phpjabbers CAR Rental ScriptAI31/7/202629/9/2026
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.
ModificadaMedia (5.1)0.28%—Phpjabbers Simple CMS17/12/202517/6/2026
PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling…
AnalizadaAlta (8.7)0.61%—Phpjabbers Simple CMS17/12/202517/6/2026
PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information.
AnalizadaCrítica (9.3)0.45%—Phpjabbers BUS Reservation System15/12/202517/6/2026
Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.
AplazadaMedia (6.1)0.26%—JabbernotificationAI5/12/202517/6/2026
The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.99-RC2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AnalizadaBaja (2.1)0.35%—Phpjabbers Restaurant Menu Maker23/9/202517/6/2026
A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and…
ModificadaMedia (5.4)0.39%—Phpjabbers Cleaning Business Software8/5/202517/6/2026
PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters.
ModificadaMedia (6.5)0.39%—Phpjabbers Event Booking Calendar8/5/202517/6/2026
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
ModificadaMedia (6.5)0.67%—Phpjabbers Event Ticketing System20/2/202517/6/2026
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
ModificadaMedia (5.4)0.29%—Phpjabbers Meeting Room Booking System20/2/202517/6/2026
PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters of&nbsp;index.php&nbsp;page.
ModificadaMedia (5.4)0.35%—Phpjabbers Event Ticketing System20/2/202517/6/2026
PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.
ModificadaAlta (8.8)0.64%—Phpjabbers Meeting Room Booking System20/2/202517/6/2026
PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.
ModificadaMedia (6.5)0.44%—Phpjabbers Cinema Booking System20/2/202517/6/2026
PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.
ModificadaMedia (5.3)0.59%—Phpjabbers Cinema Booking System20/2/202517/6/2026
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
ModificadaAlta (8.8)0.83%—Phpjabbers Cinema Booking System20/2/202517/6/2026
PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.
ModificadaMedia (4.3)0.42%—Phpjabbers Meeting Room Booking System20/2/202517/6/2026
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
ModificadaMedia (6.5)0.51%—Phpjabbers Cleaning Business Software20/2/202517/6/2026
PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.
ModificadaMedia (5.4)0.35%—Phpjabbers Cinema Booking System20/2/202517/6/2026
PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.
ModificadaMedia (6.5)0.47%—Phpjabbers Cleaning Business Software20/2/202517/6/2026
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
ModificadaMedia (6.5)0.47%—Phpjabbers Cleaning Business Software20/2/202517/6/2026
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.