CVE-2025-67649: A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting fun
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-67649
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-67649 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for A SQL injection
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-6453: The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to …nvd · 2026-08-01
- mediumCVE-2026-17555: The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the exp…nvd · 2026-08-01
- mediumCVE-2026-16614: The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is …nvd · 2026-08-01
- mediumCVE-2026-16087: The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable…nvd · 2026-08-01
- mediumCVE-2026-15951: The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parame…nvd · 2026-08-01
- mediumCVE-2026-15018: The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via …nvd · 2026-08-01
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01