Where
-Infinity
0

FreePBX FreePBX API moduleFreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module

Risk 60
Severity
7.6
First published (updated )

Sangoma FreePBXFreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports

Risk 79
Severity
8.5
First published (updated )

Sangoma FreePBXFreePBX: Authenticated Local File Inclusion in Dashboard Module

Risk 79
Severity
7.6
First published (updated )

Sangoma FreePBXFreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface

Risk 86
Severity
9.3
First published (updated )

Sangoma FreePBXFreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints

Risk 56
Severity
8.8
EPSS
0.12%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma FreePBXFreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module

Risk 56
Severity
8.8
EPSS
0.03%
First published (updated )

Sangoma FreePBXFreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports

Risk 56
Severity
8.8
EPSS
0.05%
First published (updated )

Sangoma FreePBXFreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration

Risk 49
Severity
7.5
EPSS
0.11%
First published (updated )

Sangoma FreePBXFreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes

Risk 70
Severity
7.5
First published (updated )

FreePBX Endpoint ManagerSangoma FreePBX OS Command Injection Vulnerability

Risk 87
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerFreePBX servers hacked via zero-day, emergency fix released

First published (updated )

Sangoma Freepbx Linux 7Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMG…

Risk 60
Severity
8.1
First published (updated )

FreePBX FreePBXXSS

Risk 22
Severity
4.3
First published (updated )

FreePBX FreePBXCSRF

Risk 47
Severity
6.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203