vciy

CVEs we hold for Freepbx

Records whose assigning authority named Freepbx as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-73665FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injectionFreePBX ucp
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup ModuleFreePBX backup
CVE-2026-73663FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeoverFreePBX missedcall
CVE-2026-73662Authenticated FreePBX Music RCE via mpg123 and Asterisk Call FilesFreePBX music
CVE-2026-73661FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted BackupFreePBX framework
CVE-2026-73660FreePBX: Authenticated TTS AGI Command Injection Through TTS NameFreePBX tts
CVE-2026-72578FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax DispatcherFreePBX Framework
CVE-2026-46376FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP InterfaceFreePBX security-reporting
CVE-2026-44239FreePBX: Authenticated Local File Inclusion in Dashboard ModuleFreePBX security-reporting
CVE-2026-44238FreePBX: Authenticated SQL Injection via ORDER BY in CDR ReportsFreePBX security-reporting
CVE-2026-44237FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API ModuleFreePBX security-reporting
CVE-2026-40520FreePBX api module Command Injection via GraphQLFreePBX api
CVE-2026-28287FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX EndpointsFreePBX security-reporting
CVE-2026-28284FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles ModuleFreePBX security-reporting
CVE-2026-28210FreePBX: Authenticated SQL Injection in CDR (Call Data Record) ReportsFreePBX security-reporting
CVE-2026-28209FreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integrationFreePBX security-reporting
CVE-2026-26978Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupSplFileInfo.phpFreePBX security-reporting
CVE-2025-67736Authenticated SQL Injection in FreePBX tts (Text To Speech) moduleFreePBX tts
CVE-2025-67722Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege…FreePBX framework
CVE-2025-67513FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST APIFreePBX endpoint
CVE-2025-66039FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth HeaderFreePBX framework
CVE-2025-64328FreePBX Administration GUI is Vulnerable to Authenticated Command InjectionFreePBX filestore
CVE-2025-62173Authenticated SQL Injection in Endpoint Module Rest APIFreePBX restapps
CVE-2025-61678FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameterFreePBX endpointman
CVE-2025-61675FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parametersFreePBX endpoint
CVE-2025-59429FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status pageFreePBX core
CVE-2025-59056FreePBX vulnerable to unauthenticated Denial of ServiceFreePBX framework
CVE-2025-59051FreePBX Endpoint Manager command injection via Network Scanning featureFreePBX endpoint
CVE-2025-57819FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCEFreePBX endpoint
CVE-2025-55739api: Shared OAuth Signing Key Between Different InstancesFreePBX api
CVE-2025-55211FreePBX Post-Authenticated Command InjectionFreePBX framework
CVE-2025-55210FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional ScopesFreePBX api
CVE-2025-55209FreePBX UCP is Vulnerable to Stored XSS Through its User Control PanelFreePBX contactmanager
CVE-2024-58294FreePBX 16 Authenticated Remote Code Execution via API ModuleFreePBX
CVE-2024-47071OSS Endpoint Manager allows unauthorized access to read system filesFreePBX endpointman
CVE-2021-4282FreePBX voicemail page.voicemail.php cross site scriptingFreePBX voicemail
CVE-2020-36630FreePBX cdr Cdr.class.php ajaxHandler sql injectionFreePBX cdr
CVE-2019-25090FreePBX arimanager Views cross site scriptingFreePBX arimanager

38 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.