CVE-2025-10827

MEDIUM

Phpjabbers Restaurant Menu Maker - Code Injection

Title source: rule

Description

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-94 CWE-79
Status published

Affected Products (1)

phpjabbers/restaurant_menu_maker

Timeline

Published Sep 23, 2025
Tracked Since Feb 18, 2026