VendorsSangomafreepbxany version
Vulnerabilities

Sangoma FreePBX any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

34CVEs
CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
Published 2025-08-28 · Analyzed
10.0KEV1 PoCEPSS 0.855
CVE-2014-7235
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserialize function, as exploited in the wild in September 2014.
Published 2014-10-07 · Modified
10.01 PoCEPSS 0.433
CVE-2019-19006
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
Published 2019-11-21 · Analyzed
9.8KEVEPSS 0.559
CVE-2021-45461
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.
Published 2021-12-22 · Modified
9.8EPSS 0.217
CVE-2025-66039
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
Published 2025-12-09 · Analyzed
9.8EPSS 0.033
CVE-2020-10666
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.
Published 2021-05-31 · Modified
9.8EPSS 0.022
CVE-2020-36630
FreePBX cdr Cdr.class.php ajaxHandler sql injection
Published 2022-12-25 · Modified
9.8EPSS 0.007
CVE-2026-46376
FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface
Published 2026-05-29 · Analyzed
9.8EPSS 0.005
CVE-2026-28287
FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints
Published 2026-03-05 · Analyzed
8.8EPSS 0.015
CVE-2023-43336
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
Published 2023-11-02 · Modified
8.8EPSS 0.007
CVE-2026-28210
FreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports
Published 2026-03-05 · Analyzed
8.8EPSS 0.005
CVE-2026-44238
FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports
Published 2026-05-29 · Analyzed
8.8EPSS 0.005
CVE-2026-44239
FreePBX: Authenticated Local File Inclusion in Dashboard Module
Published 2026-05-29 · Analyzed
8.8EPSS 0.005
CVE-2026-28284
FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module
Published 2026-03-05 · Analyzed
8.8EPSS 0.004
CVE-2025-55211
FreePBX Post-Authenticated Command Injection
Published 2025-09-15 · Analyzed
8.8EPSS 0.004
CVE-2025-67736
Authenticated SQL Injection in FreePBX tts (Text To Speech) module
Published 2025-12-16 · Analyzed
8.6EPSS 0.064
CVE-2025-59429
FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page
Published 2025-10-14 · Analyzed
8.5EPSS 0.002
CVE-2026-44237
FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module
Published 2026-05-29 · Analyzed
8.1EPSS 0.004
CVE-2025-67722
Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation
Published 2025-12-16 · Analyzed
7.8EPSS 0.001
CVE-2012-4869
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action.
Published 2012-09-06 · Modified
7.53 PoCEPSS 0.703
CVE-2026-28209
FreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration
Published 2026-03-05 · Analyzed
7.5EPSS 0.014
CVE-2025-59056
FreePBX vulnerable to unauthenticated Denial of Service
Published 2025-09-15 · Analyzed
7.5EPSS 0.005
CVE-2025-55210
FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes
Published 2026-02-12 · Analyzed
7.5EPSS 0.003
CVE-2019-19538
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
Published 2020-03-16 · Modified
7.2EPSS 0.031
CVE-2010-3490
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.
Published 2010-09-28 · Modified
6.51 PoCEPSS 0.094
CVE-2019-16967
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.
Published 2019-10-21 · Modified
6.1EPSS 0.013
CVE-2019-25090
FreePBX arimanager Views cross site scripting
Published 2022-12-27 · Modified
6.1EPSS 0.005
CVE-2018-15891
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
Published 2019-06-20 · Modified
4.8EPSS 0.006
CVE-2019-19852
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through 14.0.2.14, and 15.x through 15.0.15.4.
Published 2020-03-16 · Modified
4.8EPSS 0.006
CVE-2019-19615
Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administrator web site. An attacker can modify the id parameter of the backup configuration screen and embed malicious XSS code via a link. When another user (such as an admin) clicks the link, the XSS payload will render and execute in the context of the victim user's account.
Published 2020-03-16 · Modified
4.8EPSS 0.006
CVE-2019-19551
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can submit malicious values in some of the time/date formatting and time-zone fields. These fields are not being properly sanitized. If this is done and a user (such as an admin) visits the User Management screen and views that user's profile, the XSS payload will render and execute in the context of the victim user's account.
Published 2019-12-06 · Modified
4.8EPSS 0.006
CVE-2019-19552
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with sufficient privileges can edit the Display Name of a user and embed malicious XSS code. When another user (such as an admin) visits the main User Management screen, the XSS payload will render and execute in the context of the victim user's account.
Published 2019-12-06 · Modified
4.8EPSS 0.006
CVE-2019-19851
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.
Published 2020-03-16 · Modified
4.8EPSS 0.005
CVE-2012-4870
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) context parameter to panel/index_amp.php or (2) panel/dhtml/index.php; (3) clid or (4) clidname parameters to panel/flash/mypage.php; (5) PATH_INFO to admin/views/freepbx_reload.php; or (6) login parameter to recordings/index.php.
Published 2012-09-06 · Modified
4.31 PoCEPSS 0.020