Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fusionpbx

First CVE: Jun 17, 2019Active for: 7 yearsTotal CVEs: 52
44.4
VTI Score
High

Fusionpbx is a modestly represented telecommunications platform providing VoIP and communications infrastructure, where the vendor's singular product has achieved prominence among telephony deployments. The vulnerability exposure recurs consistently through a narrow set of weakness classes: cross-site scripting and path traversal flaws dominate the profile, alongside OS command injection, reflecting the web-facing administrative interface and system integration points inherent to a unified communications system. Public exploit code has a moderate tendency to emerge for these disclosures, making timely patching important for internet-exposed instances. Defenders should track this vendor's release cycles closely given its role in voice and messaging infrastructure and the recurrence of input-handling and command-execution weaknesses that can lead to authentication bypass or system compromise. Current severity, exploitation activity, and vulnerability counts are shown alongside this summary.

FAUCET AI Generated
52
Total CVEs
More Total CVEs than 98% of tracked vendors
13.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fusionpbx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2019
7 years ago
Most Recent CVE
Mar 18, 2024
858 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11409HIGH
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticat
Jun 17, 20198.887NOYES
CVE-2021-43405HIGH
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
Nov 5, 20218.858NOYES
CVE-2019-15029HIGH
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into
Sep 5, 20198.845NOYES
CVE-2022-35153CRITICAL
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
Aug 18, 20229.831NONO
CVE-2022-28055CRITICAL
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
May 4, 20229.830NONO
CVE-2019-16980HIGH
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL
Oct 21, 20198.828NONO
CVE-2021-43406HIGH
An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).
Nov 5, 20218.827NONO
CVE-2021-43404HIGH
An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters.
Nov 5, 20218.827NONO
CVE-2019-16964HIGH
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows aut
Oct 21, 20198.826NONO
CVE-2020-21057HIGH
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.
May 20, 20218.125NONO
View all 52 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products52 CVEs
75%
21%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network52 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low52 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (38.5%)
Unknown0 (0.0%)
Required32 (61.5%)
Privileges Required
Low14 (26.9%)
High4 (7.7%)
None34 (65.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
5.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fusionpbx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fusionpbx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fusionpbx's Products

View all 2 CNAs →

Top CWEs