SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-67650

HIGH · CVSS 8.6 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

Multiple PHP Jabbers scripts are vulnerable to an authenticated SQL injection due to improper input handling in sorting function parameters. This flaw allows attackers with authenticated access to execute malicious SQL queries, potentially compromising the database and sensitive data. Organizations using these scripts should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2025-67650
Severity
HIGH
CVSS
8.6
EPSS
0.28%

Original NVD Description

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.