ZeroHour

Vulnerabilities

134 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-53926
+1 in the same advisory: …53927
PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries.

PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information.

NVD description · AI analysis pending
8.7
group max
<1% PoC
  • phpjabbers simple cms
CVE-2023-53877
Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries.

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

NVD description · AI analysis pending
9.3<1% PoC ×2
  • phpjabbers bus reservation system
CVE-2025-10827
A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1.

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

NVD description · AI analysis pending
2.1<1% PoC
  • phpjabbers restaurant menu maker
CVE-2023-51328
PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters.

PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters.

NVD description · AI analysis pending
5.4<1% PoC
  • phpjabbers cleaning business software
CVE-2023-51295
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

NVD description · AI analysis pending
6.5<1% PoC
  • phpjabbers event booking calendar
CVE-2023-51339
+2 in the same advisory: …51306 …51337
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a l

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • phpjabbers event ticketing system
CVE-2023-51336
+2 in the same advisory: …51338 …51332
PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
8.8
group max
<1%
  • phpjabbers meeting room booking system
CVE-2023-51333
+3 in the same advisory: …51335 …51330 …51334
PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
8.8
group max
<1%
  • phpjabbers cinema booking system
CVE-2023-51331
+2 in the same advisory: …51327 …51326
PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
6.5<1% PoC
  • phpjabbers cleaning business software
CVE-2023-51324
+2 in the same advisory: …51323 …51325
PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • phpjabbers shared asset booking system
CVE-2023-51321
+1 in the same advisory: …51320
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email fo

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • phpjabbers night club booking software
CVE-2023-51319
+2 in the same advisory: …51316 …51318
PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • phpjabbers bus reservation system
CVE-2023-51313
+4 in the same advisory: …51314 …51317 …51315 …51312
PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • phpjabbers restaurant booking system
CVE-2023-51311
+3 in the same advisory: …51308 …51310 …51309
PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • phpjabbers car park booking system
CVE-2023-51303
PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sm

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

NVD description · AI analysis pending
6.1<1% PoC
  • phpjabbers event ticketing system
CVE-2023-51302
+4 in the same advisory: …51301 …51297 …51300 …51299
PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code.

PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • phpjabbers hotel booking system
CVE-2023-51293
+2 in the same advisory: …51296 …51298
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amoun

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • phpjabbers event booking calendar
CVE-2024-57430
+3 in the same advisory: …57428 …57427 …57429
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • phpjabbers cinema booking system
CVE-2023-48841
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

NVD description · AI analysis pending
8.81% PoC
  • phpjabbers appointment scheduler