FreePBX / Endpoint
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-67513 | FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST API | MEDIUM | 6.9 | Dec 10, 2025 |
| CVE-2025-61675 | FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters | HIGH | 8.6 | Oct 14, 2025 |
| CVE-2025-59051 | FreePBX Endpoint Manager command injection via Network Scanning feature | HIGH | 8.6 | Oct 14, 2025 |
| CVE-2025-57819 KEV | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE | CRITICAL | 10.0 | Aug 28, 2025 |
Showing 1 to 4 of 4 CVEs