CVE-2025-67650 HIGH

CVE-2025-67650: Authenticated SQL Injection in PHP Jabbers scripts

Vendor Php Jabbers
Product Appointment Scheduler
Weakness CWE-89 · SQLi
Published July 31, 2026
Last update July 31, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.

Key dates

02Disclosure timeline

July 31, 2026 CVE published

Related vulnerabilities

04Related CVE