Phpjabbers
Phpjabbers Event Booking Calendar: vulnerabilidades y CVE
Phpjabbers Event Booking Calendar tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-51295 | Media (6.5) | 0.39% | — | 8 may 2025 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. |
| CVE-2023-51298 | Media (4.7) | 0.41% | — | 19 feb 2025 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section… |
| CVE-2023-51296 | Media (6.1) | 0.46% | — | 19 feb 2025 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute… |
| CVE-2023-51293 | Alta (7.5) | 0.75% | — | 19 feb 2025 | A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible… |
| CVE-2023-40765 | Crítica (9.8) | 0.89% | — | 28 ago 2023 | User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling… |
| CVE-2014-10015 | Alta (7.5) | 1.2% | — | 13 ene 2015 | SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. |
| CVE-2014-10014 | Media (6.8) | 2.0% | — | 13 ene 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Phpjabbers
Cleaning Business Software · 9Time Slots Booking Calendar · 9Appointment Scheduler · 8Cinema Booking System · 8Availability Booking Calendar · 8CAR Rental Script · 7Fundraising Script · 7Hotel Booking System · 6Document Creator · 5CAR Park Booking System · 5Callback Widget · 5BUS Reservation System · 5