freepbx vulnerabilities
CVEs whose affected-version data names the freepbx package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-66039Critical· 9.8PoCFreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an…
▾ Abyssalsangoma · freepbxEPSS 3.3%via NVD
CVE-2025-57819Critical· 9.8CISA KEV0dayPoCFreePBX is an open-source web-based graphical user interface
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrar…
▾ Hadalsangoma · freepbxEPSS 85%via NVD