Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FreePBX — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting FreePBX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreePBX is an open-source web-based GUI that controls and manages Asterisk, an open-source telephony software suite. Primarily used by businesses and service providers to build IP-based communication systems, it simplifies complex PBX configuration through a user-friendly interface. Historically, the platform has been susceptible to critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws. These issues often stem from insufficient input validation or insecure default configurations within its modules. Notable incidents have included widespread exploitation of RCE vulnerabilities, allowing attackers to gain full system control and deploy ransomware. With 26 CVEs currently on record, the software’s security posture relies heavily on timely patching and strict access controls. Administrators must remain vigilant, as the breadth of its feature set introduces a larger attack surface compared to minimalistic telephony solutions.

CVE ID Title CVSS Severity Published
CVE-2025-64328 FreePBX Administration GUI is Vulnerable to Authenticated Command Injection — filestore CWE-78 8.3 - 2025-11-07
CVE-2025-61678 FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter — endpointman CWE-434 8.8AI High AI 2025-10-14
CVE-2025-61675 FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters — endpoint CWE-89 8.1AI High AI 2025-10-14
CVE-2025-59429 FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page — core CWE-79 6.1AI Medium AI 2025-10-14
CVE-2025-59051 FreePBX Endpoint Manager command injection via Network Scanning feature — endpoint CWE-78 8.8AI High AI 2025-10-14
CVE-2025-59056 FreePBX vulnerable to unauthenticated Denial of Service — framework CWE-22 3.8AI Low AI 2025-09-15
CVE-2025-55211 FreePBX Post-Authenticated Command Injection — framework CWE-78 7.2AI High AI 2025-09-15
CVE-2025-55739 api: Shared OAuth Signing Key Between Different Instances — api CWE-798 9.8AI Critical AI 2025-09-04
CVE-2025-55209 FreePBX UCP is Vulnerable to Stored XSS Through its User Control Panel — contactmanager CWE-79 8.2AI High AI 2025-09-04
CVE-2025-57819 FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE — endpoint CWE-89 9.8AI Critical AI 2025-08-28
CVE-2024-47071 OSS Endpoint Manager allows unauthorized access to read system files — endpointman CWE-22 6.8 Medium 2024-10-01
CVE-2019-25090 FreePBX arimanager Views cross site scripting — arimanager CWE-79 3.5 Low 2022-12-27
CVE-2021-4282 FreePBX voicemail page.voicemail.php cross site scripting — voicemail CWE-79 3.5 Low 2022-12-27
CVE-2020-36630 FreePBX cdr Cdr.class.php ajaxHandler sql injection — cdr CWE-89 5.5 Medium 2022-12-25

This page lists every published CVE security advisory associated with FreePBX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.