Vulnerabilities > Phpjabbers > Yacht Listing Script

DATE CVE VULNERABILITY TITLE RISK
2023-08-28 CVE-2023-40750 Cross-site Scripting vulnerability in PHPjabbers Yacht Listing Script 1.0
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.
network
low complexity
phpjabbers CWE-79
6.1
2023-08-28 CVE-2023-40761 Information Exposure Through an Error Message vulnerability in PHPjabbers Yacht Listing Script 2.0
User enumeration is found in PHPJabbers Yacht Listing Script v2.0.
network
low complexity
phpjabbers CWE-209
critical
9.8
2023-08-10 CVE-2023-38830 Exposure of Resource to Wrong Sphere vulnerability in PHPjabbers Yacht Listing Script 1.0
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.
network
low complexity
phpjabbers CWE-668
7.5