Phpjabbers
Phpjabbers Cinema Booking System: vulnerabilidades y CVE
Phpjabbers Cinema Booking System tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-51335 | Media (6.5) | 0.44% | — | 20 feb 2025 | PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters. |
| CVE-2023-51334 | Media (5.3) | 0.59% | — | 20 feb 2025 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service… |
| CVE-2023-51333 | Alta (8.8) | 0.83% | — | 20 feb 2025 | PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section… |
| CVE-2023-51330 | Media (5.4) | 0.35% | — | 20 feb 2025 | PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter. |
| CVE-2024-57430 | Crítica (9.8) | 0.88% | — | 6 feb 2025 | An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to… |
| CVE-2024-57429 | Media (5.4) | 0.28% | — | 6 feb 2025 | A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting… |
| CVE-2024-57428 | Crítica (9.3) | 0.76% | — | 6 feb 2025 | A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in… |
| CVE-2024-57427 | Media (6.1) | 0.45% | — | 6 feb 2025 | PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Phpjabbers
Time Slots Booking Calendar · 9Cleaning Business Software · 9Availability Booking Calendar · 8Appointment Scheduler · 8Event Booking Calendar · 7CAR Rental Script · 7Fundraising Script · 7Hotel Booking System · 6CAR Park Booking System · 5Document Creator · 5Callback Widget · 5BUS Reservation System · 5