Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreePBX — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting FreePBX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreePBX is an open-source web-based GUI that controls and manages Asterisk, an open-source telephony software suite. Primarily used by businesses and service providers to build IP-based communication systems, it simplifies complex PBX configuration through a user-friendly interface. Historically, the platform has been susceptible to critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws. These issues often stem from insufficient input validation or insecure default configurations within its modules. Notable incidents have included widespread exploitation of RCE vulnerabilities, allowing attackers to gain full system control and deploy ransomware. With 26 CVEs currently on record, the software’s security posture relies heavily on timely patching and strict access controls. Administrators must remain vigilant, as the breadth of its feature set introduces a larger attack surface compared to minimalistic telephony solutions.

Found 9 results / 38Clear Filters
HighCVE-2025-756602026-08-14
Authenticated TTS AGI Command Injection Through TTS Name · Advisory · FreePBX/security-reporting · GitHub
UnknownGHSA-hg3v-n857-mvw92026-08-14
FREEI-2970-Security - Authenticated TTS AGI Command Injection Through… · FreePBX/tts@37cf0dd · GitHub
CriticalCVE-2026-756532026-08-14
Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover · Advisor
HighGHSA-hg3v-n857-nvw92026-08-14
FREEI-2970-Security - Authenticated TTS AGI Command Injection Through… · FreePBX/tts@4057410 · GitHub
HighFREEI-29692026-08-14
FREEI-2969-Unauthenticated SQL injection · FreePBX/missedcall@4ada1d6 · GitHub
HighFREE-29692026-08-14
FREEI-2969-Unauthenticated SQL injection · FreePBX/missedcall@710acdf · GitHub
HighCVE-2026-736612026-08-14
Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup · Advisory · FreePBX/security-reporting · GitHub
Medium2026-08-14
FREEI-2972 ignore the authtype form backup · FreePBX/framework@ea684be · GitHub
HighCVE-2026-736622026-08-14
Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files · Advisory · FreePBX/security-reporting · GitHub
CriticalFREEI-29712026-08-14
FREEI-2971 RCE fix for music on hold · FreePBX/music@9f45605 · GitHub
UnknownFREEPBX-23322026-08-10
GitHub - FreePBX/framework: This module provides a facility to install bug fixes to the framework code that is not other
Critical2026-08-10
framework/amp_conf/htdocs/admin/libraries/BMO/Ajax.class.php at release/17.0 · FreePBX/framework · GitHub
CriticalGHSA-pxfc-q7zv-jhbm2026-07-17
Release v1.6.1 — Security release (superseded by v1.6.2) · mwtcmi/frogman · GitHub
CriticalCVE-2026-405152026-07-17
Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution · Advisory · mwtcmi/frogman · GitHub
HighGHSA-3p65-2prx-xfv2026-07-17
DiagnoseTrunk: endpoint_raw response may include trunk auth credentials · Issue #25 · mwtcmi/frogman
HighCVE-2024-422392026-05-29
Authenticated Local File Inclusion in Dashboard Module · Advisory · FreePBX/security-reporting · GitHub
HighGHSA-99pp-632h-c54v2026-05-29
Authenticated SQL Injection via ORDER BY in CDR Reports · Advisory · FreePBX/security-reporting · GitHub
High2026-04-21
api/Api.class.php at 5f194e39a47e5481e8947f9694304d32724175f6 · FreePBX/api · GitHub
HighFREEI-28662026-04-21
FREEI-2805 fix:sanitize shell arguments in GraphQL moduleOperations · FreePBX/api@5f194e3 · GitHub
LowGHSA-gvgh-p7wj-76cf2026-02-13
Privilege Escalation Error in GraphQL Allows Authenticated Users to Access Additional Scopes · Advisory · FreePBX/securi

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with FreePBX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.