CVE-2025-67650: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks.
This issue was fixed in the versions specified in the affected products list.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-67650
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-67650 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for An authenticated SQL
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-54368: CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and S…nvd · 2026-07-30
- criticalCVE-2026-58046: Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged …nvd · 2026-07-30
- highCVE-2026-5490: DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote at…nvd · 2026-07-29
- unknownCVE-2026-8339: A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024…nvd · 2026-07-29
- criticalCVE-2026-63234: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticat…nvd · 2026-07-29
- criticalCVE-2026-63233: A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticat…nvd · 2026-07-29
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01