Sangoma

Freepbx

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 05.03.2026 18:25:54
  • Zuletzt bearbeitet 06.03.2026 17:55:42

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This issue has been patched in versions 16.0.20 and 17....

  • EPSS 0.03%
  • Veröffentlicht 05.03.2026 18:24:50
  • Zuletzt bearbeitet 06.03.2026 18:32:58

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5.

  • EPSS 0.05%
  • Veröffentlicht 05.03.2026 18:24:06
  • Zuletzt bearbeitet 06.03.2026 18:41:03

FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. This issue has been patched in versions 16.0.49 and 17.0.7.

  • EPSS 0.16%
  • Veröffentlicht 05.03.2026 18:22:38
  • Zuletzt bearbeitet 06.03.2026 18:45:06

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerability exists in FreePBX when using the ElevenLabs Text-to-Speech (TTS) engine in the recordings module...

  • EPSS 0.05%
  • Veröffentlicht 12.02.2026 16:22:42
  • Zuletzt bearbeitet 27.02.2026 13:05:46

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authenticated users with REST/GraphQL API access. This vulner...

Medienbericht
  • EPSS 0.06%
  • Veröffentlicht 16.12.2025 00:23:05
  • Zuletzt bearbeitet 18.12.2025 17:42:21

The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 are vulnerable to SQL injection by authenticated users with administrator access. ...

  • EPSS 0.01%
  • Veröffentlicht 16.12.2025 00:14:18
  • Zuletzt bearbeitet 18.12.2025 17:45:31

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amp...

Exploit
  • EPSS 0.82%
  • Veröffentlicht 11.12.2025 21:36:11
  • Zuletzt bearbeitet 15.12.2025 17:10:56

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POS...

  • EPSS 32.61%
  • Veröffentlicht 09.12.2025 21:32:03
  • Zuletzt bearbeitet 02.02.2026 14:47:12

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary va...

  • EPSS 0.07%
  • Veröffentlicht 14.10.2025 19:26:02
  • Zuletzt bearbeitet 20.01.2026 13:59:00

FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, a reflected cross-site scripting vulnerability is present on the Asterisk HTTP Status page. The Aster...