VendorsPHPJabbersbus_reservation_systemall versions
Vulnerabilities

PHPJabbers Bus Reservation System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-53877
Bus Reservation System 1.1 Multiple SQL Injection via pickup_id Parameter
Published 2025-12-15 · Analyzed
9.8EPSS 0.004
CVE-2023-51319
PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.
Published 2025-02-20 · Modified
8.8EPSS 0.007
CVE-2023-51316
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
Published 2025-02-20 · Modified
7.5EPSS 0.007
CVE-2023-4111
PHP Jabbers Bus Reservation System index.php cross site scripting
Published 2023-08-03 · Modified
6.1EPSS 0.025
CVE-2023-51318
PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.
Published 2025-02-20 · Modified
5.4EPSS 0.004