VulnSea

security-reporting vulnerabilities

CVEs whose affected-version data names the security-reporting package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-75600High· 8.6
today

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module …

▾ TwilightFreePBX · security-reportingvia NVD
CVE-2026-54710High· 8.6
today

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers…

▾ TwilightFreePBX · security-reportingvia NVD
CVE-2026-54708High· 8.6
today

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known…

▾ TwilightFreePBX · security-reportingvia NVD
CVE-2026-54675High· 8.7
today

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform arbitrary file writes, lea…

▾ TwilightFreePBX · security-reportingvia NVD
CVE-2026-54674High· 8.6
today

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted…

▾ TwilightFreePBX · security-reportingvia NVD
CVE-2026-45562High· 7.7
today

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges …

▾ TwilightFreePBX · security-reportingvia NVD
CVE-2026-46376Critical· 9.3PoC
4mo ago

FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by …

▾ AbyssalFreePBX · security-reportingvia CVEORG
security-reporting vulnerabilities (CVEs) · VulnSea