Skip to content
Web

CVE-2025-67650

8.6
High
EPSS 0.28%Patch availableJul 31, 2026

Authenticated SQL injection in PHP Jabbers scripts enabling DB compromise.

common questions

Is CVE-2025-67650 being exploited?

Not confirmed. CVE-2025-67650 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.28% probability of exploitation in the next 30 days.

How severe is CVE-2025-67650?

CVE-2025-67650 is rated High with a CVSS score of 8.6. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.

Is there a patch for CVE-2025-67650?

Yes. A fix has been recorded for CVE-2025-67650. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.

What does CVE-2025-67650 affect?

CVE-2025-67650 affects PHP Jabbers web scripts (multiple products), Self-hosted PHP Jabbers installations, Web servers and databases running vulnerable PHP Jabbers apps. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.

What should I do about CVE-2025-67650?

Apply vendor updates immediately, rotate DB credentials, audit logs and restrict admin access.

Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.

executive summary
technical analysis
affected
PHP Jabbers web scripts (multiple products)Self-hosted PHP Jabbers installationsWeb servers and databases running vulnerable PHP Jabbers apps
impact

Authenticated attacker can execute arbitrary SQL, exfiltrate/modify data, and potentially escalate access via database manipulation.

action required

Immediate action required

affected versions
PHP Jabbers Appointment Scheduler
  • affected< 4.1
PHP Jabbers Auto Classifieds Script
  • affected< 4.1
PHP Jabbers Availability Booking Calendar
  • affected< 6.1
PHP Jabbers Availability Calendar
  • affected< 6.1
PHP Jabbers Business Directory Script
  • affected< 4.1
PHP Jabbers Bus Reservation System
  • affected< 2.1
PHP Jabbers Car Park Booking System
  • affected< 4.1
PHP Jabbers Car Rental Script
  • affected< 4.1
PHP Jabbers Cinema Booking System
  • affected< 2.1
PHP Jabbers Cleaning Business Software
  • affected< 2.1
PHP Jabbers Equipment Rental Script
  • affected< 2.1
PHP Jabbers Event Booking Calendar
  • affected< 5.1
PHP Jabbers Event Ticketing System
  • affected< 2.1
PHP Jabbers Food Delivery Script
  • affected< 4.1
PHP Jabbers Hotel Booking System
  • affected< 5.1
PHP Jabbers Job Listing Script
  • affected< 4.1
PHP Jabbers Limo Booking Software
  • affected< 2.1
PHP Jabbers Meeting Room Booking System
  • affected< 2.1
PHP Jabbers Member Directory Script
  • affected< 2.1
PHP Jabbers Member Login Script
  • affected< 4.1
PHP Jabbers PHP Event Calendar
  • affected< 4.1
PHP Jabbers PHP Newsletter Script
  • affected< 5.1
PHP Jabbers PHP Shopping Cart
  • affected< 6.0
PHP Jabbers Product Comparison Script
  • affected< 2.1
PHP Jabbers Property Listing Script
  • affected< 4.1
PHP Jabbers Rental Property Booking Calendar
  • affected< 3.1
PHP Jabbers Restaurant Booking System
  • affected< 4.1
PHP Jabbers Service Booking Script
  • affected< 2.1
PHP Jabbers Shuttle Booking Software
  • affected< 3.1
PHP Jabbers Taxi Booking Script
  • affected< 3.1
PHP Jabbers Ticket Support Script
  • affected< 4.1
PHP Jabbers Time Slots Booking Calendar
  • affected< 5.1
PHP Jabbers Travel Tours Script
  • affected< 3.1
PHP Jabbers Vacation Rental Script
  • affected< 5.1
PHP Jabbers Yacht Listing Script
  • affected< 3.1

As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free