Phpjabbers · Restaurant Menu Maker · CVE-2025-10827
**Name of the Vulnerable Software and Affected Versions**
PHPJabbers Restaurant Menu Maker versions up to 1.1
**Description**
A cross-site scripting issue exists in PHPJabbers Restaurant Menu Maker. The issue is related to the `/preview.php` file and manipulation of the `theme` parameter. This manipulation can lead to cross-site scripting, and the attack can be initiated remotely. The exploit has been publicly released.
**Recommendations**
Versions prior to 1.1 should be updated.