freepbx
Communicationsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting freepbx.
- CVE-2026-73665FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection
- CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
- CVE-2026-73663FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
- CVE-2026-73662Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files
- CVE-2026-73661FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
- CVE-2026-73660FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
- CVE-2026-72578FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher8.8
- CVE-2026-44237FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module8.1
- CVE-2026-44238FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports8.8
- CVE-2026-44239FreePBX: Authenticated Local File Inclusion in Dashboard Module8.8
- CVE-2026-46376FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface9.8
- CVE-2026-26978Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupSplFileInfo.php
- CVE-2026-40520FreePBX api module Command Injection via GraphQL7.2
- CVE-2026-28287FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints8.8
- CVE-2026-28284FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module8.8