Phpjabbers
Phpjabbers Cleaning Business Software: vulnerabilidades y CVE
Phpjabbers Cleaning Business Software tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-51328 | Media (5.4) | 0.38% | — | 8 may 2025 | PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters. |
| CVE-2023-51331 | Media (6.5) | 0.51% | — | 20 feb 2025 | PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section… |
| CVE-2023-51327 | Media (6.5) | 0.47% | — | 20 feb 2025 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service… |
| CVE-2023-51326 | Media (6.5) | 0.47% | — | 20 feb 2025 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service… |
| CVE-2023-36140 | Crítica (9.8) | 0.53% | — | 11 sept 2023 | In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. |
| CVE-2023-36141 | Media (5.3) | 0.58% | — | 4 ago 2023 | User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not,… |
| CVE-2023-36139 | Crítica (9.8) | 0.45% | — | 4 ago 2023 | In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. |
| CVE-2023-36138 | Media (6.1) | 0.44% | — | 4 ago 2023 | PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php. |
| CVE-2023-4115 | Media (6.1) | 8.4% | — | 3 ago 2023 | A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument index leads to cross site… |