Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpjabbers

First CVE: Oct 23, 2008Active for: 18 yearsTotal CVEs: 140
32.8
VTI Score
Medium

Phpjabbers develops a focused line of web-based business-management applications spanning appointment scheduling, booking systems, and specialized platforms such as cinema ticketing and cleaning-business software. Despite a narrow product portfolio, the vendor's presence in the vulnerability landscape is notably prominent, reflecting the widespread deployment of these scheduling and booking tools across small and medium-sized businesses. Vulnerabilities affecting Phpjabbers skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency toward public exploit availability, driven by a recurring pattern of web-application flaws: cross-site scripting and SQL injection in input handling, sensitive information disclosure in error messages, resource-exhaustion conditions, and formula-injection risks in CSV generation. These weakness classes are characteristic of web applications that accept and process user input with insufficient sanitization and validation, creating direct attack paths for threat actors. Defenders should prioritize patches for Phpjabbers products—particularly those exposed to the internet—and treat scheduling and booking systems as routine targets for exploitation; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
140
Total CVEs
More Total CVEs than 99% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpjabbers over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2008
17 years ago
Most Recent CVE
Dec 17, 2025
219 days ago

Products(37 total)

Top CVEs

Signals from CVEs in this vendor scope (140 CVEs).

140 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4116MEDIUM
A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipula
Aug 3, 20236.140NOYES
CVE-2023-4115MEDIUM
A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argum
Aug 3, 20236.140NOYES
CVE-2023-4114MEDIUM
A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The m
Aug 3, 20236.140NOYES
CVE-2023-40749CRITICAL
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
Aug 28, 20239.838NOYES
CVE-2023-40748CRITICAL
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
Aug 28, 20239.838NOYES
CVE-2023-4113MEDIUM
A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipu
Aug 3, 20236.137NOYES
CVE-2023-4112MEDIUM
A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation
Aug 3, 20236.137NOYES
CVE-2023-53926CRITICAL
PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted
Dec 17, 20259.834NONO
CVE-2023-53877CRITICAL
Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-bas
Dec 15, 20259.834NONO
CVE-2020-22225CRITICAL
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
Nov 5, 20219.831NONO
View all 140 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products140 CVEs
57%
21%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network134 (95.7%)
Unknown6 (4.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low134 (95.7%)
High0 (0.0%)
Unknown6 (4.3%)
User Interaction
None71 (50.7%)
Unknown6 (4.3%)
Required63 (45.0%)
Privileges Required
Low36 (25.7%)
High0 (0.0%)
None98 (70.0%)
Unknown6 (4.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (140 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
15 CVEs
10.7% of CVEs· 96th percentile
ExploitDB
11 CVEs
7.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpjabbers.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpjabbers — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpjabbers's Products

View all 3 CNAs →

Top CWEs