FreePBX / Framework
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-73661 | FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup | HIGH | 8.6 | Aug 13, 2026 |
| CVE-2025-67722 | Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation | MEDIUM | 5.7 | Dec 16, 2025 |
| CVE-2025-66039 | FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header | CRITICAL | 9.3 | Dec 9, 2025 |
| CVE-2025-59056 | FreePBX vulnerable to unauthenticated Denial of Service | MEDIUM | 6.6 | Sep 15, 2025 |
| CVE-2025-55211 | FreePBX Post-Authenticated Command Injection | MEDIUM | 6.3 | Sep 15, 2025 |
Showing 1 to 5 of 5 CVEs