CRITICAL 9.3 NVD
CVE-2025-67649
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters respons
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
References
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-07-31 via NVD.
Risk Timeline
CVE Disclosed2026-07-31 · 3 days ago
Remediation Resources
Official Advisory
cert.pl/en/posts/2026/07/CVE-2025-67649/Analysis & PoC
www.phpjabbers.com/car-rental-script/
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.