Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

3cx

First CVE: Aug 3, 2009Active for: 17 yearsTotal CVEs: 34
36.3
VTI Score
Medium

3CX maintains a focused portfolio of unified communications and call-center products, including its phone system, web server, and live chat platform, that sit on the perimeter of enterprise networks and handle sensitive authentication and customer data. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the internet-facing nature and feature density of communications middleware. The exposure recurs across the product line through weakness classes including cross-site scripting, path traversal, unsafe file upload, and cleartext storage of credentials, which are characteristic of web-facing communication applications and present direct risks to deployed instances. Defenders should prioritize patching this vendor's releases and inventory instances exposed to untrusted networks, particularly where the platform handles user authentication or customer interactions. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 3cx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2009
16 years ago
Most Recent CVE
May 3, 2024
812 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-15359MEDIUM
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" a
Oct 18, 20176.534NOYES
CVE-2022-28005CRITICAL
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrar
May 6, 20229.833NONO
CVE-2019-11185CRITICAL
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrar
Jun 3, 20199.833NONO
CVE-2019-12498CRITICAL
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
Mar 20, 20209.831NONO
CVE-2019-14950MEDIUM
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
Aug 12, 20196.131NOYES
CVE-2018-12426CRITICAL
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demon
Jul 2, 20189.831NONO
CVE-2023-49954CRITICAL
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.
Dec 25, 20239.830NONO
CVE-2022-27438HIGH
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerabil
Jun 6, 20228.129NONO
CVE-2023-29059HIGH
3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron W
Mar 30, 20237.828NONO
CVE-2021-45490CRITICAL
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.
Mar 28, 20229.128NONO
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
53%
29%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (8.8%)
Network28 (82.4%)
Unknown3 (8.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (88.2%)
High1 (2.9%)
Unknown3 (8.8%)
User Interaction
None19 (55.9%)
Unknown3 (8.8%)
Required12 (35.3%)
Privileges Required
Low8 (23.5%)
High0 (0.0%)
None23 (67.6%)
Unknown3 (8.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.9% of CVEs· 95th percentile
ExploitDB
1 CVE
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 3cx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 3cx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 3cx's Products

View all 3 CNAs →

Top CWEs