Where
-Infinity
0

Sangoma Switchvox SMB EditionAuthenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal

Risk 33
Severity
7
EPSS
0.24%
First published (updated )

Sangoma Switchvox SMB EditionAuthenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal

Risk 29
Severity
7.1
EPSS
0.23%
First published (updated )

Sangoma Switchvox SMB EditionUnauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

Risk 59
Severity
9.3
EPSS
0.41%
First published (updated )

Sangoma Switchvox SMB EditionUnauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal

Risk 44
Severity
8.6
EPSS
0.33%
First published (updated )

FreePBX FreePBX API moduleFreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module

Risk 60
Severity
7.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma FreePBXFreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports

Risk 79
Severity
8.5
First published (updated )

Sangoma FreePBXFreePBX: Authenticated Local File Inclusion in Dashboard Module

Risk 79
Severity
7.6
First published (updated )

Sangoma FreePBXFreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface

Risk 86
Severity
9.3
First published (updated )

Sangoma SwitchvoxSangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

Risk 18
Severity
3.2
First published (updated )

Sangoma FreePBX api moduleFreePBX api module Command Injection via GraphQL

Risk 79
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma FreePBXFreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints

Risk 56
Severity
8.8
EPSS
0.12%
First published (updated )

Sangoma FreePBXFreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module

Risk 56
Severity
8.8
EPSS
0.03%
First published (updated )

Sangoma FreePBXFreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports

Risk 56
Severity
8.8
EPSS
0.05%
First published (updated )

Sangoma FreePBXFreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration

Risk 49
Severity
7.5
EPSS
0.11%
First published (updated )

Sangoma FreePBXFreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes

Risk 70
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma Certified Asteriskast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation

Risk 56
Severity
8.8
EPSS
0.02%
First published (updated )

Sangoma Certified AsteriskAsterisk vulnerable to potential privilege escalation

Risk 51
Severity
7.8
EPSS
0.02%
First published (updated )

Sangoma Certified AsteriskAsterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection

Risk 27
Severity
6.5
EPSS
0.10%
First published (updated )

Sangoma Certified AsteriskThe Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization

Risk 27
Severity
6.1
EPSS
0.03%
First published (updated )

Sangoma FreePBX Authenticated SQL Injection in FreePBX tts (Text To Speech) module

Risk 72
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma FreePBX Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation

Risk 69
Severity
7.8
First published (updated )

FreePBX FreePBX 16FreePBX 16 Authenticated Remote Code Execution via API Module

Risk 79
Severity
8.8
First published (updated )

FreePBX Endpoint ManagerSangoma FreePBX OS Command Injection Vulnerability

Risk 87
Severity
8.6
First published (updated )

Sangoma FreePBX FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page

Risk 78
Severity
8.5
First published (updated )

Sangoma Certified AsteriskAsterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Sangoma FreePBX FreePBX vulnerable to unauthenticated Denial of Service

Risk 43
Severity
7.5
First published (updated )

FreePBX FreePBXFreePBX Post-Authenticated Command Injection

Risk 79
Severity
8.8
First published (updated )

Sangoma FreePBX Sangoma FreePBX Authentication Bypass Vulnerability

Risk 100
Severity
10
First published (updated )

Sangoma AsteriskAsterisk can crash from a specifically malformed Authorization header in an incoming SIP request

Risk 43
Severity
7.5
First published (updated )

Sangoma Certified AsteriskAsterisk remotely exploitable leak of RTP UDP ports and internal resources

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203