Freepbx
Freepbx: vulnerabilities and CVEs
Freepbx has 25 published vulnerabilities, 14 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs25
Last 12 months14
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75600 | High (8.6) | 0.76% | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access… |
| CVE-2026-54710 | High (8.6) | 0.45% | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing… |
| CVE-2026-54708 | High (8.6) | 0.45% | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server.… |
| CVE-2026-54675 | High (8.7) | 0.60% | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform… |
| CVE-2026-54674 | High (8.6) | 0.60% | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using… |
| CVE-2026-45562 | High (7.7) | 0.30% | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands… |
| CVE-2026-73665 | Critical (9.3) | 0.41% | — | Aug 13, 2026 | FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace.… |
| CVE-2026-73664 | High (8.6) | 0.51% | — | Aug 13, 2026 | FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to… |
| CVE-2026-73663 | Critical (9.3) | 1.7% | — | Aug 13, 2026 | FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in… |
| CVE-2026-73662 | High (7.6) | 0.64% | — | Aug 13, 2026 | FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in… |
| CVE-2026-73661 | High (8.6) | 0.60% | — | Aug 13, 2026 | FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in… |
| CVE-2026-73660 | High (7.5) | 0.77% | — | Aug 13, 2026 | FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during… |
| CVE-2026-46516 | Medium (4.8) | 0.44% | — | Jul 20, 2026 | Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js/chat.js`'s `formatMarkdown`) inserted regex capture groups as raw HTML in four template patterns:… |
| CVE-2026-26978 | High (8.6) | 0.97% | — | May 18, 2026 | FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully… |
| CVE-2025-55739 | Medium (5.1) | 0.42% | — | Sep 5, 2025 | api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key… |
| CVE-2025-55209 | Medium (5.1) | 0.36% | — | Sep 4, 2025 | contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site… |
| CVE-2018-15891 | Medium (4.8) | 0.56% | — | Jun 20, 2019 | An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name. |
| CVE-2014-7235 | High (10) | 43% | — | Oct 7, 2014 | htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth… |
| CVE-2014-1903 | High (7.5) | 53% | — | Feb 18, 2014 | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which… |
| CVE-2009-4458 | Medium (4.3) | 1.8% | — | Dec 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech parameter to… |
| CVE-2009-1803 | Medium (5) | 1.2% | — | May 28, 2009 | FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to… |
| CVE-2009-1802 | Medium (6.8) | 0.58% | — | May 28, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentication of admins for requests that create… |
| CVE-2009-1801 | Medium (4.3) | 1.3% | — | May 28, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to inject arbitrary web script or HTML via the (1) display parameter… |
| CVE-2007-2350 | Medium (6.5) | 2.3% | — | Apr 30, 2007 | admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter. |
| CVE-2007-2191 | Medium (6.8) | 4.5% | — | Apr 24, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.