Vulnerabilities > Phpjabbers > Time Slots Booking Calendar

DATE CVE VULNERABILITY TITLE RISK
2023-12-07 CVE-2023-48826 Injection vulnerability in PHPjabbers Time Slots Booking Calendar 4.0
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
network
low complexity
phpjabbers CWE-74
8.8
2023-12-07 CVE-2023-48827 Cross-site Scripting vulnerability in PHPjabbers Time Slots Booking Calendar 4.0
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
network
low complexity
phpjabbers CWE-79
5.4
2023-12-07 CVE-2023-48828 Cross-site Scripting vulnerability in PHPjabbers Time Slots Booking Calendar 4.0
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
network
low complexity
phpjabbers CWE-79
5.4
2023-12-07 CVE-2023-48833 Resource Exhaustion vulnerability in PHPjabbers Time Slots Booking Calendar 4.0
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
network
low complexity
phpjabbers CWE-400
7.5
2023-08-01 CVE-2023-33560 Cross-site Scripting vulnerability in PHPjabbers Time Slots Booking Calendar 3.3
There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
network
low complexity
phpjabbers CWE-79
6.1
2023-08-01 CVE-2023-33561 Unspecified vulnerability in PHPjabbers Time Slots Booking Calendar 3.3
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
network
low complexity
phpjabbers
critical
9.8
2023-08-01 CVE-2023-33562 Unspecified vulnerability in PHPjabbers Time Slots Booking Calendar 3.3
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3.
network
low complexity
phpjabbers
critical
9.8
2023-08-01 CVE-2023-33563 Improper Authentication vulnerability in PHPjabbers Time Slots Booking Calendar 3.3
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
network
low complexity
phpjabbers CWE-287
8.8
2023-08-01 CVE-2023-33564 Cross-site Scripting vulnerability in PHPjabbers Time Slots Booking Calendar 3.3
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
network
low complexity
phpjabbers CWE-79
6.1