VendorsPHPJabbersevent_ticketing_system1.0
Vulnerabilities

PHPJabbers Event Ticketing System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-51339
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
Published 2025-02-20 · Modified
6.5EPSS 0.007
CVE-2023-51303
PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
Published 2025-02-19 · Modified
6.1EPSS 0.005
CVE-2023-51306
PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters.
Published 2025-02-20 · Modified
5.4EPSS 0.004
CVE-2023-51337
PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.
Published 2025-02-20 · Modified
5.4EPSS 0.003