20
I Use This!
Activity Not Available
Analyzed about 2 years ago. based on code collected over 3 years ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2026-46376 Critical May 29, 2026 FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) u more...
13.0, 15.0.16.42, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2026-44239 High May 29, 2026 FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied more...
13.0, 15.0.16.42, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2026-44238 High May 29, 2026 FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parame more...
13.0, 15.0.16.42, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2026-44237 High May 29, 2026 FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials dur more...
13.0, 15.0.16.42, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2025-66039 Critical Dec 09, 2025 FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the aut more...
13.0, 15.0.16.42, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2025-59429 Medium Oct 14, 2025 FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, a more...
13.0, 15.0.16.42, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2023-43336 High Nov 02, 2023 Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified paramet more...
13.0, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2019-25090 Medium Dec 27, 2022 A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of t more...
13.0, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002
CVE-2019-19852 Medium Mar 16, 2020 An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the more...
13.0
CVE-2019-19851 Medium Mar 16, 2020 An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/con more...
13.0, 14.0.10.3, 2.3.1, 1.10.010, 1.10.006, 1.10.005, 1.10.004, 1.10.003, 1.10.002