Vulnerabilities (CVE)

Filtered by vendor Phpjabbers Subscribe
Filtered by product Event Ticketing System
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-51303 1 Phpjabbers 1 Event Ticketing System 2025-04-23 N/A 6.1 MEDIUM
PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
CVE-2023-51306 1 Phpjabbers 1 Event Ticketing System 2025-04-23 N/A 5.4 MEDIUM
PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters.
CVE-2023-51339 1 Phpjabbers 1 Event Ticketing System 2025-04-17 N/A 6.5 MEDIUM
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
CVE-2023-51337 1 Phpjabbers 1 Event Ticketing System 2025-04-10 N/A 5.4 MEDIUM
PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.