---
id: CVE-2025-67651
title: >-
  A Cross-Site Request Forgery (CSRF) vulnerability has been identified in
  multiple PHP Jabbers scripts
summary: >-
  A Cross-Site Request Forgery (CSRF) vulnerability has been identified in
  multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite
  attributes allows an attacker to send unauthorized requests in the context of
  an authe…
severity: none
cwe:
  - CWE-352
published: '2026-07-31'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:10:00.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67651'
references:
  - url: 'https://cert.pl/en/posts/2026/07/CVE-2025-67649/'
    label: cvd@cert.pl
  - url: 'https://www.phpjabbers.com/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00223
epssPercentile: 0.11606
ingestedAt: '2026-09-29T14:36:14.070Z'
---

## Overview

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.


This issue was fixed in the versions specified in the affected products list.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
