CVE-2026-97818
- EPSS 0.32%
- Veröffentlicht 25.09.2026 04:44:18
- Zuletzt bearbeitet 06.10.2026 22:10:00
phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
CVE-2026-67602
- EPSS 0.35%
- Veröffentlicht 24.08.2026 13:57:42
- Zuletzt bearbeitet 24.09.2026 20:43:32
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone witho...
CVE-2026-75105
- EPSS 0.28%
- Veröffentlicht 17.08.2026 20:36:01
- Zuletzt bearbeitet 24.09.2026 20:02:50
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is us...
CVE-2026-12194
- EPSS 0.25%
- Veröffentlicht 04.07.2026 06:54:21
- Zuletzt bearbeitet 06.07.2026 19:43:54
PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.
CVE-2026-4189
- EPSS 0.26%
- Veröffentlicht 15.03.2026 19:32:12
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in phpipam up to 1.7.4. The impacted element is an unknown function of the file app/admin/sections/edit-result.php of the component Section Handler. Executing a manipulation of the argument subnetOrdering can lead to sq...
CVE-2025-61078
- EPSS 0.26%
- Veröffentlicht 09.12.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 02:17:18
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.
CVE-2025-60912
- EPSS 0.2%
- Veröffentlicht 08.12.2025 00:00:00
- Zuletzt bearbeitet 10.12.2025 17:36:31
phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump...
CVE-2024-55093
- EPSS 0.23%
- Veröffentlicht 31.03.2025 13:15:42
- Zuletzt bearbeitet 23.04.2025 18:32:54
phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.
CVE-2024-10721
- EPSS 0.34%
- Veröffentlicht 20.03.2025 10:11:07
- Zuletzt bearbeitet 01.04.2025 20:35:45
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which can be executed in the context of other users who view th...
CVE-2024-10727
- EPSS 0.34%
- Veröffentlicht 20.03.2025 10:10:58
- Zuletzt bearbeitet 01.04.2025 20:35:36
A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the application receives data in an HTTP request and includes that data within the immediate response in an uns...