
CVE-2025-66683
A Cross-Site Request Forgery (CSRF) vulnerability exists in the administrator profile update functionality of CarRentalMS v2.0. The affected endpoint…

A Cross-Site Request Forgery (CSRF) vulnerability exists in the administrator profile update functionality of CarRentalMS v2.0. The affected endpoint…

Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

Proof-of-concept for stored XSS in Unifiedtransform v2.0's Create Assignment function, demonstrating remote code execution via malicious PDF upload…

CVE-2024-57428: PHPJabbers Cinema Booking System v2.0 suffers from stored XSS, enabling persistent JavaScript injection for phishing and malware…

CVE-2024-57427: PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected XSS, allowing session hijacking and phishing attacks.