Phpipam
This hub aggregates every CVE we track for Phpipam, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
55
CVEs tracked
8
Critical
9
High
0
In CISA KEV
Severity distribution
MEDIUM34HIGH9CRITICAL8LOW3
Monthly trend
0
2
0
0
0
10
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
1
2
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Phpipam.
- CVE-2026-67602phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache9.1
- CVE-2026-75105phpIPAM Temporary Subnet Share Information Disclosure via Address Parameter7.5
- CVE-2026-12194PHPIPAM Authenticated LFI
- CVE-2025-61078Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instru...6.1
- CVE-2025-60912phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, a...3.3
- CVE-2024-55093phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.5.4
- CVE-2024-10721Store XSS in phpipam/phpipam5.4
- CVE-2024-10727Cross-Site Scripting (XSS) in phpipam/phpipam6.1
- CVE-2024-10720Stored Cross-site Scripting (XSS) in phpipam/phpipam6.1
- CVE-2024-10722Stored Cross-site Scripting (XSS) in phpipam/phpipam5.4
- CVE-2024-10719Stored Cross-site Scripting (XSS) in phpipam/phpipam5.4
- CVE-2024-10718Cookie without Secure attribute in phpipam/phpipam7.5
- CVE-2024-10724Stored XSS in IPV6 Section in phpipam/phpipam5.4
- CVE-2024-10723Stored XSS in phpipam/phpipam5.4
- CVE-2024-10725Stored Cross-site Scripting (XSS) in phpipam/phpipam5.4
Product normalization is registry-driven with AI assist and human review. How it works