PHP Jabbers vulnerabilities
5 CVEs tracked
PHP Jabbers appears in recent reports with critical web vulnerabilities across multiple products, notably the PHP Poll Script and Car Rental Script. The issues include authenticated SQL injection (CVE-2026-46593, CVE-2025-67650), unauthenticated SQL injection (CVE-2025-67649), reflected XSS (CVE-2026-46594), and CSRF (CVE-2025-67651). Defenders should prioritize patching all PHP Jabbers-based systems to the latest versions, strengthening input validation on critical endpoints like `pjAdminPolls.controller.php`, and ensuring CSRF protection mechanisms are properly implemented.
Azərbaycanca: PHP Jabbers son hesabatlarda, əsasən, PHP Poll Script və Car Rental Script daxil olmaqla bir neçə məhsulunda kritik veb zəiflikləri ilə bağlı diqqət çəkir. Bu zəifliklər autentifikasiya olunmuş SQL injection (CVE-2026-46593, CVE-2025-67650), autentifikasiya olunmamış SQL injection (CVE-2025-67649), əks olunan XSS (CVE-2026-46594) və CSRF (CVE-2025-67651) hücumlarını əhatə edir. Müdafiəçilər PHP Jabbers əsaslı sistemlərin dərhal ən son versiyalara yenilənməsinə diqqət etməli, xüsusilə `pjAdminPolls.controller.php` kimi kritik uç nöqtələrində giriş validasiyasını gücləndirməli və CSRF müdafiə mexanizmlərinin aktiv olduğundan əmin olmalıdırlar.
This vendor's CVEs5
This hub is built from skopnix's own reporting on PHP Jabbers: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.