Phpjabbers develops a focused line of web-based business-management applications spanning appointment scheduling, booking systems, and specialized platforms such as cinema ticketing and cleaning-business software. Despite a narrow product portfolio, the vendor's presence in the vulnerability landscape is notably prominent, reflecting the widespread deployment of these scheduling and booking tools across small and medium-sized businesses. Vulnerabilities affecting Phpjabbers skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency toward public exploit availability, driven by a recurring pattern of web-application flaws: cross-site scripting and SQL injection in input handling, sensitive information disclosure in error messages, resource-exhaustion conditions, and formula-injection risks in CSV generation. These weakness classes are characteristic of web applications that accept and process user input with insufficient sanitization and validation, creating direct attack paths for threat actors. Defenders should prioritize patches for Phpjabbers products—particularly those exposed to the internet—and treat scheduling and booking systems as routine targets for exploitation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpjabbers over time
Signals from CVEs in this vendor scope (140 CVEs).
140 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4116MEDIUM A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipula | Aug 3, 2023 | 6.1 | 40 | NO | YES |
CVE-2023-4115MEDIUM A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argum | Aug 3, 2023 | 6.1 | 40 | NO | YES |
CVE-2023-4114MEDIUM A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The m | Aug 3, 2023 | 6.1 | 40 | NO | YES |
CVE-2023-40749CRITICAL PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. | Aug 28, 2023 | 9.8 | 38 | NO | YES |
CVE-2023-40748CRITICAL PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. | Aug 28, 2023 | 9.8 | 38 | NO | YES |
CVE-2023-4113MEDIUM A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipu | Aug 3, 2023 | 6.1 | 37 | NO | YES |
CVE-2023-4112MEDIUM A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation | Aug 3, 2023 | 6.1 | 37 | NO | YES |
CVE-2023-53926CRITICAL PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2023-53877CRITICAL Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-bas | Dec 15, 2025 | 9.8 | 34 | NO | NO |
CVE-2020-22225CRITICAL Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. | Nov 5, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (140 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpjabbers.
Media articles that mention a CVE ID that affects a product developed by Phpjabbers — matched by CVE ID, not by vendor name.