Skip to main content

Vendor/product archive

sangoma / freepbx CVEs

Beta · best-effort

42 CVEs tagged to sangoma / freepbx7 Critical, 15 High, 17 Medium, 3 Low, 0 Unrated.

CVE-2026-46376

Published May 29, 2026

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial temp…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44239

Published May 29, 2026

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitiza…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44238

Published May 29, 2026

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44237

Published May 29, 2026

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledg…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28287

Published Mar 5, 2026

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the rec…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28284

Published Mar 5, 2026

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has be…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28210

Published Mar 5, 2026

FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. This issue has been patched in…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28209

Published Mar 5, 2026

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerability exists in FreePBX when us…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55210

Published Feb 12, 2026

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege esca…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-67736

Published Dec 16, 2025

The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 are vulnera…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67722

Published Dec 16, 2025

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local pr…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58294

Published Dec 11, 2025

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Atta…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66039

Published Dec 9, 2025

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-59429

Published Oct 14, 2025

FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, a reflected cross-site scripti…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59056

Published Sep 15, 2025

FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the unins…

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-55211

Published Sep 15, 2025

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary she…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57819

Published Aug 28, 2025

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthent…

CVSS 10.0 · Critical
evidence mentions
8
Buzz score
82.9
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-53564

Published Dec 2, 2024

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwant…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-43336

Published Nov 2, 2023

Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing ext…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25090

Published Dec 27, 2022

A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Views Handler.…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-36630

Published Dec 25, 2022

A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.php. The manipulation of the arg…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45461

Published Dec 22, 2021

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2020-10666

Published May 31, 2021

The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19852

Published Mar 16, 2020

An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=ce…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19615

Published Mar 16, 2020

Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administ…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2