NA - CVE-2023-51300 - PHPJabbers Hotel Booking System v4.0 is...
PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.
NA - CVE-2023-51301 - A lack of rate limiting in the "Login Section,...
A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user,...
NA - CVE-2023-51302 - PHPJabbers Hotel Booking System v4.0 is...
PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on...
NA - CVE-2023-51303 - PHPJabbers Event Ticketing System v1.0 is...
PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
NA - CVE-2025-25196 - OpenFGA is a high-performance and flexible...
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are...
NA - CVE-2025-27090 - Sliver is an open source cross-platform...
Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver...
NA - CVE-2023-51305 - PHPJabbers Car Park Booking System v3.0 is...
PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.
NA - CVE-2024-37359 - The web server receives a URL or similar...
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the...
NA - CVE-2024-37360 - Hitachi Vantara Pentaho Business Analytics...
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or...