---
id: CVE-2025-67650
title: >-
  An authenticated SQL injection vulnerability has been identified in multiple
  PHP Jabbers scripts
summary: >-
  An authenticated SQL injection vulnerability has been identified in multiple
  PHP Jabbers scripts. Improper neutralization of input provided by an
  authenticated user into parameters responsible for sorting functions allows an
  attacker to …
severity: none
cwe:
  - CWE-89
published: '2026-07-31'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:10:00.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67650'
references:
  - url: 'https://cert.pl/en/posts/2026/07/CVE-2025-67649/'
    label: cvd@cert.pl
  - url: 'https://www.phpjabbers.com/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00383
epssPercentile: 0.29801
ingestedAt: '2026-09-29T14:36:14.070Z'
---

## Overview

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks.
This issue was fixed in the versions specified in the affected products list.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
