CVE-2025-67651
published 2026-07-31CVE-2025-67651: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite…
PriorityP433medium6.9CVSS 4.0
AVNACLATNPRNUIAVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.17%
6.3th percentile
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.
This issue was fixed in the versions specified in the affected products list.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| php_jabbers | appointment_scheduler | < 4.1 | 4.1 |
| php_jabbers | auto_classifieds_script | < 4.1 | 4.1 |
| php_jabbers | availability_booking_calendar | < 6.1 | 6.1 |
| php_jabbers | availability_calendar | < 6.1 | 6.1 |
| php_jabbers | bus_reservation_system | < 2.1 | 2.1 |
| php_jabbers | business_directory_script | < 4.1 | 4.1 |
| php_jabbers | car_park_booking_system | < 4.1 | 4.1 |
| php_jabbers | car_rental_script | < 4.1 | 4.1 |
| php_jabbers | cinema_booking_system | < 2.1 | 2.1 |
| php_jabbers | cleaning_business_software | < 2.1 | 2.1 |
| php_jabbers | equipment_rental_script | < 2.1 | 2.1 |
| php_jabbers | event_booking_calendar | < 5.1 | 5.1 |
| php_jabbers | event_ticketing_system | < 2.1 | 2.1 |
| php_jabbers | food_delivery_script | < 4.1 | 4.1 |
| php_jabbers | hotel_booking_system | < 5.1 | 5.1 |
| php_jabbers | job_listing_script | < 4.1 | 4.1 |
| php_jabbers | limo_booking_software | < 2.1 | 2.1 |
| php_jabbers | meeting_room_booking_system | < 2.1 | 2.1 |
| php_jabbers | member_directory_script | < 2.1 | 2.1 |
| php_jabbers | member_login_script | < 4.1 | 4.1 |
| php_jabbers | php_event_calendar | < 4.1 | 4.1 |
| php_jabbers | php_newsletter_script | < 5.1 | 5.1 |
| php_jabbers | php_shopping_cart | < 6.0 | 6.0 |
| php_jabbers | product_comparison_script | < 2.1 | 2.1 |
| php_jabbers | property_listing_script | < 4.1 | 4.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts.
ghsa_unreviewed·2026-07-31
CVE-2025-67651 [MEDIUM] CWE-352 A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.
This issue was fixed in the versions specified in the affected products list.
VulDB
PHP Jabbers Appointment Scheduler cross-site request forgery
vuldb·2026-07-31·CVSS 6.9
CVE-2025-67651 [MEDIUM] PHP Jabbers Appointment Scheduler cross-site request forgery
A vulnerability classified as problematic was found in PHP Jabbers Appointment Scheduler, Availability Booking Calendar, Availability Calendar, Bus Reservation System, Car Park Booking System, Car Rental Script, Cinema Booking System, Cleaning Business Software, Equipment Rental Script, Event Booking Calendar, Event Ticketing System, Food Delivery Script, Hotel Booking System, Job Listing Script, Limo Booking Software, Member Directory Script, Member Login Script, Meeting Room Booking System, PHP Event Calendar, PHP Newsletter Script, PHP Shopping Cart, Product Comparison Script, Property Listing Script, Rental Property Booking Calendar, Restaurant Booking System, Service Booking Script, Shuttle Booking Software, Taxi Booking Script, Ticket Support Script, Time Slots Booking Calendar, Trav
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-31
Published