Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freepbx

First CVE: Apr 24, 2007Active for: 19 yearsTotal CVEs: 13
33.2
VTI Score
Medium

FreePBX is a widely deployed open-source IP PBX platform offering communication and call-management functionality across an often-overlooked tier of business infrastructure, and its vulnerability profile concentrates in web-facing administrative and API components where input-handling and access-control weaknesses recur. The durable signal across the platform centers on application-level flaws including cross-site scripting, cross-site request forgery, code injection, and information exposure—typical of web-accessible management interfaces—and these vulnerabilities frequently acquire public exploit code. Defenders should treat FreePBX instances as security-sensitive assets requiring restricted network access and prompt patching; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freepbx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2007
19 years ago
Most Recent CVE
Apr 21, 2026
94 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-1903HIGH
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions
Feb 18, 20147.567NOYES
CVE-2014-7235HIGH
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to
Oct 7, 201410.059NOYES
CVE-2026-40520HIGH
FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directl
Apr 21, 20268.830NONO
CVE-2007-2191MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-A
Apr 24, 20076.828NOYES
CVE-2009-4458MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via th
Dec 30, 20094.322NOYES
CVE-2019-16967MEDIUM
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an
Oct 21, 20196.121NONO
CVE-2019-16966MEDIUM
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\mod
Oct 21, 20196.121NONO
CVE-2018-15891MEDIUM
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript co
Jun 20, 20194.818NONO
CVE-2009-1802MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentica
May 28, 20096.818NONO
CVE-2007-2350MEDIUM
admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter
Apr 30, 20076.518NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
77%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (38.5%)
Unknown8 (61.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (38.5%)
High0 (0.0%)
Unknown8 (61.5%)
User Interaction
None1 (7.7%)
Unknown8 (61.5%)
Required4 (30.8%)
Privileges Required
Low1 (7.7%)
High2 (15.4%)
None2 (15.4%)
Unknown8 (61.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freepbx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freepbx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freepbx's Products

View all 2 CNAs →

Top CWEs