logo

Vulnerabilities in PHP Jabbers scripts

ID: 26c2b801-41a2-58e9-aa20-fa01116e5b1a

STIX ID: report--26c2b801-41a2-58e9-aa20-fa01116e5b1a

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

Author: CERT Polska

...
...

CERT Polska coordinated disclosure of multiple vulnerabilities in PHP Jabbers products: unauthenticated and authenticated SQL injection issues (CWE-89) including CVE-2025-67649 and CVE-2026-46593, reflected XSS in the PHP Poll Script (CVE-2026-46594), and CSRF issues across multiple scripts (CVE-2025-67651); affected versions are fixed in the listed releases (commonly 4.1), and the report credits Kamil Szczurowski and Robert Kruczek.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.