Skip to main content

Vendor/product archive

phpjabbers / appointment_scheduler CVEs

Beta · best-effort

8 CVEs tagged to phpjabbers / appointment_scheduler0 Critical, 3 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2023-48839

Published Dec 7, 2023

Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36127

Published Oct 10, 2023

User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10010

Published Jan 13, 2015

Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10001

Published Jan 13, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for reques…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1