VendorsPHPJabbersavailability_booking_calendar5.0
Vulnerabilities

PHPJabbers Availability Booking Calendar 5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-36131
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
Published 2023-08-03 · Modified
9.8EPSS 0.009
CVE-2023-36132
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
Published 2023-08-03 · Modified
9.8EPSS 0.009
CVE-2023-36133
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
Published 2023-08-03 · Modified
9.8EPSS 0.009
CVE-2023-48207
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
Published 2023-12-07 · Modified
8.8EPSS 0.012
CVE-2023-48831
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
Published 2023-12-07 · Modified
7.5EPSS 0.012
CVE-2023-4110
PHP Jabbers Availability Booking Calendar index.php cross site scripting
Published 2023-08-03 · Modified
6.1EPSS 0.018
CVE-2023-48208
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
Published 2023-12-07 · Modified
6.1EPSS 0.005
CVE-2023-48825
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Published 2023-12-07 · Modified
5.4EPSS 0.005