FreePBX is a widely deployed open-source IP PBX platform offering communication and call-management functionality across an often-overlooked tier of business infrastructure, and its vulnerability profile concentrates in web-facing administrative and API components where input-handling and access-control weaknesses recur. The durable signal across the platform centers on application-level flaws including cross-site scripting, cross-site request forgery, code injection, and information exposure—typical of web-accessible management interfaces—and these vulnerabilities frequently acquire public exploit code. Defenders should treat FreePBX instances as security-sensitive assets requiring restricted network access and prompt patching; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freepbx over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-1903HIGH admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions | Feb 18, 2014 | 7.5 | 67 | NO | YES |
CVE-2014-7235HIGH htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to | Oct 7, 2014 | 10.0 | 59 | NO | YES |
CVE-2026-40520HIGH FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directl | Apr 21, 2026 | 8.8 | 30 | NO | NO |
CVE-2007-2191MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-A | Apr 24, 2007 | 6.8 | 28 | NO | YES |
CVE-2009-4458MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via th | Dec 30, 2009 | 4.3 | 22 | NO | YES |
CVE-2019-16967MEDIUM An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an | Oct 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-16966MEDIUM An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\mod | Oct 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-15891MEDIUM An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript co | Jun 20, 2019 | 4.8 | 18 | NO | NO |
CVE-2009-1802MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentica | May 28, 2009 | 6.8 | 18 | NO | NO |
CVE-2007-2350MEDIUM admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter | Apr 30, 2007 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freepbx.
Media articles that mention a CVE ID that affects a product developed by Freepbx — matched by CVE ID, not by vendor name.