CVE-2025-67736High· 7.2▾ TwilightThe FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 are vulnerable to SQL injection by authenticated users with administr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 1.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
6.4%
The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 are vulnerable to SQL injection by authenticated users with administrator access. Authenticated users with administrative access to the Administrator Control Panel (ACP) can leverage this SQL injection vulnerability to extract sensitive information from the database and execute code on the system as the asterisk user with chained elevation to root privileges. Users should upgrade to version 16.0.5 or 17.0.5 to receive a fix.
freepbx >= 16.0, < 16.0.5freepbx >= 17.0, < 17.0.5Upgrade past the affected range:
freepbx 17.0.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67722High· 7.8FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk
CVE-2025-57819Critical· 9.8FreePBX is an open-source web-based graphical user interface
CVE-2025-66039Critical· 9.8FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems
CVE-2026-9586Critical· 9.8An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …
CVE-2025-11611Medium· 6.3A weakness has been identified in SourceCodester Simple Inventory System 1.0
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0