Showing 3 vulnerabilities on this page for Availability Booking Calendar

Signals CISA KEV Ransomware Nuclei
PHP Jabbers vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CSRF in PHP Jabbers scripts

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.

CWE-352Jul 31, 2026
CVSS6.9v4.0EPSS0.166%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Authenticated SQL Injection in PHP Jabbers scripts

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.

CWE-89Jul 31, 2026
CVSS8.6v4.0EPSS0.279%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

PHP Jabbers Availability Booking Calendar index.php cross site scripting

A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CWE-79Aug 3, 20231 related artifact
CVSS3.5v3.1EPSS1.79%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX