<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T01:13:19.889129+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-67651</id>
    <title>CVE-2025-67651 — CSRF in PHP Jabbers scripts</title>
    <updated>2026-10-10T01:13:19.890645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PHP Jabbers Appointment Scheduler, PHP Jabbers Bus Reservation System, PHP Jabbers Car Park Booking System, PHP Jabbers Car Rental Script, PHP Jabbers Cinema Booking System, PHP Jabbers Event Booking Calendar, PHP Jabbers Event Ticketing System, PHP Jabbers Hotel Booking System, PHP Jabbers Cleaning Business Software, PHP Jabbers Equipment Rental Script and 25 more</p>
<p>A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.</p>
<p>This issue was fixed in the versions specified in the affected products list.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-67651"/>
  </entry>
</feed>
