CVE Feed

    Dashboard / CVE / CVE-2025-67651

    CVE-2025-67651

    A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.

    Published:Jul 31, 2026
    Last Modified:Jul 31, 2026
    EPS:Jul 31, 2026
    EPSS Score:
    CVSS Score:6.9

    Affected Products

    Vendor
    Php Jabbers
    Product
    Appointment Scheduler
    Vendor
    Php Jabbers
    Product
    Auto Classifieds Script
    Vendor
    Php Jabbers
    Product
    Availability Booking Calendar
    Vendor
    Php Jabbers
    Product
    Availability Calendar
    Vendor
    Php Jabbers
    Product
    Bus Reservation System
    Vendor
    Php Jabbers
    Product
    Business Directory Script
    Vendor
    Php Jabbers
    Product
    Car Park Booking System
    Vendor
    Php Jabbers
    Product
    Car Rental Script
    Vendor
    Php Jabbers
    Product
    Cinema Booking System
    Vendor
    Php Jabbers
    Product
    Cleaning Business Software
    Vendor
    Php Jabbers
    Product
    Equipment Rental Script
    Vendor
    Php Jabbers
    Product
    Event Booking Calendar
    Vendor
    Php Jabbers
    Product
    Event Ticketing System
    Vendor
    Php Jabbers
    Product
    Food Delivery Script
    Vendor
    Php Jabbers
    Product
    Hotel Booking System
    Vendor
    Php Jabbers
    Product
    Job Listing Script
    Vendor
    Php Jabbers
    Product
    Limo Booking Software
    Vendor
    Php Jabbers
    Product
    Meeting Room Booking System
    Vendor
    Php Jabbers
    Product
    Member Directory Script
    Vendor
    Php Jabbers
    Product
    Member Login Script
    Vendor
    Php Jabbers
    Product
    Php Event Calendar
    Vendor
    Php Jabbers
    Product
    Php Newsletter Script
    Vendor
    Php Jabbers
    Product
    Php Shopping Cart
    Vendor
    Php Jabbers
    Product
    Product Comparison Script
    Vendor
    Php Jabbers
    Product
    Property Listing Script
    Vendor
    Php Jabbers
    Product
    Rental Property Booking Calendar
    Vendor
    Php Jabbers
    Product
    Restaurant Booking System
    Vendor
    Php Jabbers
    Product
    Service Booking Script
    Vendor
    Php Jabbers
    Product
    Shuttle Booking Software
    Vendor
    Php Jabbers
    Product
    Taxi Booking Script
    Vendor
    Php Jabbers
    Product
    Ticket Support Script
    Vendor
    Php Jabbers
    Product
    Time Slots Booking Calendar
    Vendor
    Php Jabbers
    Product
    Travel Tours Script
    Vendor
    Php Jabbers
    Product
    Vacation Rental Script
    Vendor
    Php Jabbers
    Product
    Yacht Listing Script

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High