CVE-2025-67651
- EPSS 0.17%
- Veröffentlicht 31.07.2026 11:40:44
- Zuletzt bearbeitet 31.07.2026 20:16:45
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user...
CVE-2025-67650
- EPSS 0.28%
- Veröffentlicht 31.07.2026 11:40:40
- Zuletzt bearbeitet 31.07.2026 20:16:45
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL I...
CVE-2023-48838
- EPSS 0.47%
- Veröffentlicht 07.12.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 08:32:32
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
CVE-2023-48839
- EPSS 0.42%
- Veröffentlicht 07.12.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 08:32:32
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
CVE-2023-48840
- EPSS 1.05%
- Veröffentlicht 07.12.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 08:32:32
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
CVE-2023-48841
- EPSS 1.22%
- Veröffentlicht 07.12.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 08:32:32
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
CVE-2023-36126
- EPSS 0.38%
- Veröffentlicht 10.10.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 08:09:19
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
CVE-2023-36127
- EPSS 0.59%
- Veröffentlicht 10.10.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 08:09:19
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with vali...
- EPSS 7.65%
- Veröffentlicht 13.01.2015 11:59:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.
CVE-2014-10001
- EPSS 2.26%
- Veröffentlicht 13.01.2015 11:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][...