Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FreePBX — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting FreePBX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreePBX is an open-source web-based GUI that controls and manages Asterisk, an open-source telephony software suite. Primarily used by businesses and service providers to build IP-based communication systems, it simplifies complex PBX configuration through a user-friendly interface. Historically, the platform has been susceptible to critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws. These issues often stem from insufficient input validation or insecure default configurations within its modules. Notable incidents have included widespread exploitation of RCE vulnerabilities, allowing attackers to gain full system control and deploy ransomware. With 26 CVEs currently on record, the software’s security posture relies heavily on timely patching and strict access controls. Administrators must remain vigilant, as the breadth of its feature set introduces a larger attack surface compared to minimalistic telephony solutions.

CVE ID Title CVSS Severity Published
CVE-2026-75600 FreePBX: Authenticated API generatedocs Host Command Injection — security-reporting CWE-78 8.6 High 2026-09-28
CVE-2026-54710 FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion) — security-reporting CWE-20 8.6 High 2026-09-28
CVE-2026-54708 Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module — security-reporting CWE-22 8.6 High 2026-09-28
CVE-2026-54675 FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Module — security-reporting CWE-22 8.7 High 2026-09-28
CVE-2026-54674 Authenticated Command Injection in FreePBX UCP Interface — security-reporting CWE-78 8.6 High 2026-09-28
CVE-2026-45562 FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module — security-reporting CWE-78 7.7 High 2026-09-28
CVE-2026-73665 FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection — ucp CWE-862 9.3 Critical 2026-08-13
CVE-2026-73664 FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module — backup CWE-269 8.6 High 2026-08-13
CVE-2026-73663 FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover — missedcall CWE-89 9.3 Critical 2026-08-13
CVE-2026-73662 Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files — music CWE-78 7.6 High 2026-08-13
CVE-2026-73661 FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup — framework CWE-15 8.6 High 2026-08-13
CVE-2026-73660 FreePBX: Authenticated TTS AGI Command Injection Through TTS Name — tts CWE-78 7.5 High 2026-08-13
CVE-2026-72578 FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher — FreePBX Framework CWE-352 8.8 High 2026-08-10
CVE-2026-44237 FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module — security-reporting CWE-1390 - - 2026-05-29
CVE-2026-44238 FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports — security-reporting CWE-89 - - 2026-05-29
CVE-2026-44239 FreePBX: Authenticated Local File Inclusion in Dashboard Module — security-reporting CWE-98 - - 2026-05-29
CVE-2026-46376 FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface — security-reporting CWE-798 9.3 Critical 2026-05-29
CVE-2026-26978 Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupSplFileInfo.php — security-reporting CWE-502 - - 2026-05-18
CVE-2026-40520 FreePBX api module Command Injection via GraphQL — api CWE-78 7.2 High 2026-04-21
CVE-2026-28287 FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints — security-reporting CWE-78 8.8 - 2026-03-05
CVE-2026-28284 FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module — security-reporting CWE-89 8.8 - 2026-03-05
CVE-2026-28210 FreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports — security-reporting CWE-89 8.8 - 2026-03-05
CVE-2026-28209 FreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration — security-reporting CWE-78 8.8 - 2026-03-05
CVE-2025-55210 FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes — api CWE-270 8.8AI High AI 2026-02-12
CVE-2025-67736 Authenticated SQL Injection in FreePBX tts (Text To Speech) module — tts CWE-89 7.2AI High AI 2025-12-16
CVE-2025-67722 Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation — framework CWE-426 7.8AI High AI 2025-12-16
CVE-2024-58294 FreePBX 16 Authenticated Remote Code Execution via API Module — FreePBX CWE-78 8.8AI High AI 2025-12-11
CVE-2025-67513 FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST API — endpoint CWE-521 9.8AI Critical AI 2025-12-10
CVE-2025-66039 FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header — framework CWE-287 7.4AI High AI 2025-12-09
CVE-2025-62173 Authenticated SQL Injection in Endpoint Module Rest API — restapps CWE-89 8.8AI High AI 2025-12-03

This page lists every published CVE security advisory associated with FreePBX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.