CVE-2025-67650
published 2026-07-31CVE-2025-67650: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated…
PriorityP348high8.6CVSS 4.0
AVNACLATNPRHUINVCHVIHVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.28%
20.6th percentile
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks.
This issue was fixed in the versions specified in the affected products list.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| php_jabbers | appointment_scheduler | < 4.1 | 4.1 |
| php_jabbers | auto_classifieds_script | < 4.1 | 4.1 |
| php_jabbers | availability_booking_calendar | < 6.1 | 6.1 |
| php_jabbers | availability_calendar | < 6.1 | 6.1 |
| php_jabbers | bus_reservation_system | < 2.1 | 2.1 |
| php_jabbers | business_directory_script | < 4.1 | 4.1 |
| php_jabbers | car_park_booking_system | < 4.1 | 4.1 |
| php_jabbers | car_rental_script | < 4.1 | 4.1 |
| php_jabbers | cinema_booking_system | < 2.1 | 2.1 |
| php_jabbers | cleaning_business_software | < 2.1 | 2.1 |
| php_jabbers | equipment_rental_script | < 2.1 | 2.1 |
| php_jabbers | event_booking_calendar | < 5.1 | 5.1 |
| php_jabbers | event_ticketing_system | < 2.1 | 2.1 |
| php_jabbers | food_delivery_script | < 4.1 | 4.1 |
| php_jabbers | hotel_booking_system | < 5.1 | 5.1 |
| php_jabbers | job_listing_script | < 4.1 | 4.1 |
| php_jabbers | limo_booking_software | < 2.1 | 2.1 |
| php_jabbers | meeting_room_booking_system | < 2.1 | 2.1 |
| php_jabbers | member_directory_script | < 2.1 | 2.1 |
| php_jabbers | member_login_script | < 4.1 | 4.1 |
| php_jabbers | php_event_calendar | < 4.1 | 4.1 |
| php_jabbers | php_newsletter_script | < 5.1 | 5.1 |
| php_jabbers | php_shopping_cart | < 6.0 | 6.0 |
| php_jabbers | product_comparison_script | < 2.1 | 2.1 |
| php_jabbers | property_listing_script | < 4.1 | 4.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
PHP Jabbers Appointment Scheduler sql injection
vuldb·2026-07-31·CVSS 8.6
CVE-2025-67650 [HIGH] PHP Jabbers Appointment Scheduler sql injection
A vulnerability marked as critical has been reported in PHP Jabbers Appointment Scheduler, Bus Reservation System, Car Park Booking System, Car Rental Script, Cinema Booking System, Event Booking Calendar, Event Ticketing System, Hotel Booking System, Cleaning Business Software, Equipment Rental Script, Food Delivery Script, Member Login Script, Member Directory Script, Availability Calendar, PHP Event Calendar, PHP Newsletter Script, Product Comparison Script, Ticket Support Script, PHP Shopping Cart, Auto Classifieds Script, Business Directory Script, Availability Booking Calendar, Time Slots Booking Calendar, Restaurant Booking System, Shuttle Booking Software, Meeting Room Booking System, Rental Property Booking Calendar, Service Booking Script, Limo Booking Software, Taxi Booking Scri
GHSA
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts.
ghsa_unreviewed·2026-07-31
CVE-2025-67650 [HIGH] CWE-89 An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts.
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks.
This issue was fixed in the versions specified in the affected products list.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-31
Published