Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

security-reporting — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in security-reporting, with AI-generated Chinese analysis, references, and POCs.

This page is an entry point for the security-reporting product, focusing on vulnerability aggregation across various vendors and weakness types. It collects reports detailing software flaws, configuration errors, and implementation defects that have been publicly disclosed or tracked by security researchers. The data spans a comprehensive time range, capturing historical incidents as well as recent discoveries to provide a complete timeline of security issues. By accessing this resource, users can effectively track a vendor's advisory history, observe how specific products have responded to emerging threats, and monitor patterns in reported vulnerabilities. This aggregation allows analysts to understand the broader context of a weakness class by seeing how it manifests across different systems and environments. Users can look up a product's vulnerability history to assess its security maturity over time, identify recurring themes in patching behaviors, and compare the frequency and severity of issues among similar vendors. The collected information helps in building a clearer picture of the risk landscape, supporting better decision-making for threat modeling and risk mitigation strategies. This page serves as a centralized reference point for those needing detailed insights into reported security flaws without the noise of unrelated data. It is designed for security professionals, developers, and analysts who require accurate, structured information to support their investigation and remediation efforts.

Vendor: FreePBX

CVE ID Title CVSS Severity Published
CVE-2026-75600 FreePBX: Authenticated API generatedocs Host Command Injection CWE-78 8.6 High 2026-09-28
CVE-2026-54710 FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion) CWE-20 8.6 High 2026-09-28
CVE-2026-54708 Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module CWE-22 8.6 High 2026-09-28
CVE-2026-54675 FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Module CWE-22 8.7 High 2026-09-28
CVE-2026-54674 Authenticated Command Injection in FreePBX UCP Interface CWE-78 8.6 High 2026-09-28
CVE-2026-45562 FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module CWE-78 7.7 High 2026-09-28
CVE-2026-44237 FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module CWE-1390 - - 2026-05-29
CVE-2026-44238 FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports CWE-89 - - 2026-05-29
CVE-2026-44239 FreePBX: Authenticated Local File Inclusion in Dashboard Module CWE-98 - - 2026-05-29
CVE-2026-46376 FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface CWE-798 9.3 Critical 2026-05-29
CVE-2026-26978 Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupSplFileInfo.php CWE-502 - - 2026-05-18
CVE-2026-28287 FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints CWE-78 8.8 - 2026-03-05
CVE-2026-28284 FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module CWE-89 8.8 - 2026-03-05
CVE-2026-28210 FreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports CWE-89 8.8 - 2026-03-05
CVE-2026-28209 FreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration CWE-78 8.8 - 2026-03-05

All 15 known CVE vulnerabilities affecting security-reporting with full Chinese analysis, references, and POCs where available.