3CX maintains a focused portfolio of unified communications and call-center products, including its phone system, web server, and live chat platform, that sit on the perimeter of enterprise networks and handle sensitive authentication and customer data. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the internet-facing nature and feature density of communications middleware. The exposure recurs across the product line through weakness classes including cross-site scripting, path traversal, unsafe file upload, and cleartext storage of credentials, which are characteristic of web-facing communication applications and present direct risks to deployed instances. Defenders should prioritize patching this vendor's releases and inventory instances exposed to untrusted networks, particularly where the platform handles user authentication or customer interactions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 3cx over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15359MEDIUM In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" a | Oct 18, 2017 | 6.5 | 34 | NO | YES |
CVE-2022-28005CRITICAL An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrar | May 6, 2022 | 9.8 | 33 | NO | NO |
CVE-2019-11185CRITICAL The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrar | Jun 3, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-12498CRITICAL The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism. | Mar 20, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-14950MEDIUM The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. | Aug 12, 2019 | 6.1 | 31 | NO | YES |
CVE-2018-12426CRITICAL The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demon | Jul 2, 2018 | 9.8 | 31 | NO | NO |
CVE-2023-49954CRITICAL The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address. | Dec 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-27438HIGH Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerabil | Jun 6, 2022 | 8.1 | 29 | NO | NO |
CVE-2023-29059HIGH 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron W | Mar 30, 2023 | 7.8 | 28 | NO | NO |
CVE-2021-45490CRITICAL The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation. | Mar 28, 2022 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 3cx.
Media articles that mention a CVE ID that affects a product developed by 3cx — matched by CVE ID, not by vendor name.