PT-2025-39095 · Phpjabbers · Restaurant Menu Maker

Nyxswl

·

Published

2025-09-23

·

Updated

2025-09-23

·

CVE-2025-10827

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPJabbers Restaurant Menu Maker versions up to 1.1
Description A cross-site scripting issue exists in PHPJabbers Restaurant Menu Maker. The issue is related to the /preview.php file and manipulation of the theme parameter. This manipulation can lead to cross-site scripting, and the attack can be initiated remotely. The exploit has been publicly released.
Recommendations Versions prior to 1.1 should be updated.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10827

Affected Products

Restaurant Menu Maker