3cx
Security Risk Profile
72
/100
highSecurity Risk Score
Comprehensive risk assessment based on 36 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 3, 2009 to present
36
Total CVEs
18
Critical+High
0
Exploited
17
Unpatched
Threat Assessment
Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
17
Critical/High
Risk Level
72/100
high
Severity Distribution
Critical
8High
10Medium
18Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
XSS
12
2
Path Traversal
4
3
Malicious File Upload
2
4
SQL Injection
1
5
Command Injection
1
Most Affected Products
1. 3CX 3CX17
2. 3CX Live Chat Wordpress13
3. 3CX 3cx Macos4
4. 3CX Phone System4
5. 3CX 3cx Windows3
Recent Vulnerabilities
See more →CVE-2023-27362
CVSS 7.8high
3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability
5/3/2024🔧 No Patch
CVE-2023-49954
CVSS 9.8critical
12/25/2023🔧 No Patch
ZDI-23-1153
CVSS 7.0high
3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability
8/21/2023🔧 No Patch
ZDI-CAN-20026
CVSS 7.0high
ZDI-23-1153: 3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability
8/21/2023🔧 No Patch
CVE-2022-48482
CVSS 7.5high
5/2/2023🔧 No Patch
CVE-2022-48483
CVSS 7.5high
5/2/2023🔧 No Patch
CVE-2023-29059
CVSS 7.8high
3/30/2023🔧 No Patch
CVE-2019-9972
CVSS 9.0critical
6/7/2022🔧 No Patch
CVE-2019-9971
CVSS 9.0critical
6/7/2022🔧 No Patch
CVE-2022-27438
CVSS 8.1high
6/6/2022🔧 No Patch
Monitor 3cx in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.