Where
-Infinity
0

FreePBX FreePBX API moduleFreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module

Risk 60
Severity
7.6
First published (updated )

FreePBX FreePBXFree PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupSplFileInfo.php

Risk 62
Severity
8.6
First published (updated )

Sangoma FreePBX api moduleFreePBX api module Command Injection via GraphQL

Risk 79
Severity
8.6
First published (updated )

Sangoma FreePBXFreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints

Risk 56
Severity
8.8
EPSS
0.12%
First published (updated )

Sangoma FreePBXFreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module

Risk 56
Severity
8.8
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma FreePBXFreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports

Risk 56
Severity
8.8
EPSS
0.05%
First published (updated )

Sangoma FreePBXFreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration

Risk 49
Severity
7.5
EPSS
0.11%
First published (updated )

Sangoma FreePBXFreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes

Risk 70
Severity
7.5
First published (updated )

Sangoma FreePBX Authenticated SQL Injection in FreePBX tts (Text To Speech) module

Risk 72
Severity
8.6
First published (updated )

Sangoma FreePBX Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

FreePBX FreePBX 16FreePBX 16 Authenticated Remote Code Execution via API Module

Risk 79
Severity
8.8
First published (updated )

FreePBX FreePBX Endpoint ManagerFreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header

Risk 89
Severity
9.8
First published (updated )

FreePBX Endpoint ManagerSangoma FreePBX OS Command Injection Vulnerability

Risk 87
Severity
8.6
First published (updated )

FreePBX Endpoint ManagerFreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter

Risk 65
Severity
8.6
First published (updated )

FreePBX Endpoint ManagerFreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters

Risk 65
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma FreePBX FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page

Risk 78
Severity
8.5
First published (updated )

FreePBX Endpoint ManagerFreePBX Endpoint Manager command injection via Network Scanning feature

Risk 65
Severity
8.6
First published (updated )

Sangoma FreePBX FreePBX vulnerable to unauthenticated Denial of Service

Risk 43
Severity
7.5
First published (updated )

FreePBX FreePBXFreePBX Post-Authenticated Command Injection

Risk 79
Severity
8.8
First published (updated )

You Already Have Our Personal Data, Take Our Phone Calls Too (FreePBX CVE-2025-57819) - watchTowr Labs

First published (updated )
Social
reddit
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

FreePBX FreePBXapi: Shared OAuth Signing Key Between Different Instances

Risk 40
Severity
5.1
First published (updated )

FreePBX FreePBXFreePBX UCP is Vulnerable to Stored XSS Through its User Control Panel

Risk 40
Severity
5.1
First published (updated )

Sangoma FreePBX Sangoma FreePBX Authentication Bypass Vulnerability

Risk 100
Severity
10
First published (updated )

FreePBX FreePBXMalicious File Upload

Risk 66
Severity
7.2
First published (updated )

FreePBX ManagerXSS

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

FreePBX Contactmanager FreepbxXSS

Risk 38
Severity
6.1
First published (updated )

Sangoma FreePBX XSS

Risk 29
Severity
4.8
First published (updated )

FreePBX DISASQL Injection

Risk 41
Severity
6
First published (updated )

FreePBX FreePBXCode Injection

Risk 87
Severity
10
First published (updated )

FreePBX FreePBXadmin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 befor…

Risk 52
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203