| CVE ID | CVE-2025-67649 |
| Publication date | 31 July 2026 |
| Vendor | PHP Jabbers |
| Product | Car Rental Script |
| Vulnerable versions | All before 4.1 |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2025-67650 |
| Publication date | 31 July 2026 |
| Vendor | PHP Jabbers |
| Product | Multiple products |
| Vulnerable versions | Product dependent |
| Vulnerability type (CWE) | Improper neutralization of special elements used in an SQL command ('SQL injection') (CWE-89) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2025-67651 |
| Publication date | 31 July 2026 |
| Vendor | PHP Jabbers |
| Product | Multiple products |
| Vulnerable versions | Product dependent |
| Vulnerability type (CWE) | Cross-Site Request Forgery (CSRF) (CWE-352) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-46593 |
| Publication date | 31 July 2026 |
| Vendor | PHP Jabbers |
| Product | PHP Poll Script |
| Vulnerable versions | All before 4.1 |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-46594 |
| Publication date | 31 July 2026 |
| Vendor | PHP Jabbers |
| Product | PHP Poll Script |
| Vulnerable versions | All before 4.1 |
| Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in multiple PHP Jabbers scripts and participated in coordination of their disclosure.
The vulnerability CVE-2025-67649: A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script. Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
The vulnerability CVE-2026-46593: A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
The vulnerability CVE-2026-46594: A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
This issue was fixed in version 4.1.
The vulnerability CVE-2025-67650: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list in a CVE entry.
The vulnerability CVE-2025-67651: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list in a CVE entry.
These two vulnerabilities were fixed in versions specified in the following table:
| # | Product | Fixed Version |
|---|---|---|
| 1 | Appointment Scheduler | 4.1 |
| 2 | Bus Reservation System | 2.1 |
| 3 | Car Park Booking System | 4.1 |
| 4 | Car Rental Script | 4.1 |
| 5 | Cinema Booking System | 2.1 |
| 6 | Event Booking Calendar | 5.1 |
| 7 | Event Ticketing System | 2.1 |
| 8 | Hotel Booking System | 5.1 |
| 9 | Cleaning Business Software | 2.1 |
| 10 | Equipment Rental Script | 2.1 |
| 11 | Food Delivery Script | 4.1 |
| 12 | Member Login Script | 4.1 |
| 13 | Member Directory Script | 2.1 |
| 14 | Availability Calendar | 6.1 |
| 15 | PHP Event Calendar | 4.1 |
| 16 | PHP Newsletter Script | 5.1 |
| 17 | Product Comparison Script | 2.1 |
| 18 | Ticket Support Script | 4.1 |
| 19 | PHP Shopping Cart | 6.0 |
| 20 | Auto Classifieds Script | 4.1 |
| 21 | Business Directory Script | 4.1 |
| 22 | Availability Booking Calendar | 6.1 |
| 23 | Time Slots Booking Calendar | 5.1 |
| 24 | Restaurant Booking System | 4.1 |
| 25 | Shuttle Booking Software | 3.1 |
| 26 | Meeting Room Booking System | 2.1 |
| 27 | Rental Property Booking Calendar | 3.1 |
| 28 | Service Booking Script | 2.1 |
| 29 | Limo Booking Software | 2.1 |
| 30 | Taxi Booking Script | 3.1 |
| 31 | Job Listing Script | 4.1 |
| 32 | Property Listing Script | 4.1 |
| 33 | Travel Tours Script | 3.1 |
| 34 | Vacation Rental Script | 5.1 |
| 35 | Yacht Listing Script | 3.1 |
Credits
We thank Kamil Szczurowski and Robert Kruczek for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.