CVE-2025-67651: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.
This issue was fixed in the versions specified in the affected products list.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-67651
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-67651 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for A Cross-Site Request
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-15988: The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerab…nvd · 2026-08-01
- mediumCVE-2025-14469: The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi…nvd · 2026-08-01
- highCVE-2026-66416: Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated…nvd · 2026-07-30
- mediumCVE-2026-44613: Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configura…nvd · 2026-07-30
- highCVE-2026-14980: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-si…nvd · 2026-07-30
- highCVE-2026-5219: Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co.…nvd · 2026-07-30
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01