Fusionpbx is a modestly represented telecommunications platform providing VoIP and communications infrastructure, where the vendor's singular product has achieved prominence among telephony deployments. The vulnerability exposure recurs consistently through a narrow set of weakness classes: cross-site scripting and path traversal flaws dominate the profile, alongside OS command injection, reflecting the web-facing administrative interface and system integration points inherent to a unified communications system. Public exploit code has a moderate tendency to emerge for these disclosures, making timely patching important for internet-exposed instances. Defenders should track this vendor's release cycles closely given its role in voice and messaging infrastructure and the recurrence of input-handling and command-execution weaknesses that can lead to authentication bypass or system compromise. Current severity, exploitation activity, and vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fusionpbx over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11409HIGH app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticat | Jun 17, 2019 | 8.8 | 87 | NO | YES |
CVE-2021-43405HIGH An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric). | Nov 5, 2021 | 8.8 | 58 | NO | YES |
CVE-2019-15029HIGH FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into | Sep 5, 2019 | 8.8 | 45 | NO | YES |
CVE-2022-35153CRITICAL FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php. | Aug 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-28055CRITICAL Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function. | May 4, 2022 | 9.8 | 30 | NO | NO |
CVE-2019-16980HIGH In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL | Oct 21, 2019 | 8.8 | 28 | NO | NO |
CVE-2021-43406HIGH An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values). | Nov 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-43404HIGH An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters. | Nov 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-16964HIGH app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows aut | Oct 21, 2019 | 8.8 | 26 | NO | NO |
CVE-2020-21057HIGH Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php. | May 20, 2021 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fusionpbx.
Media articles that mention a CVE ID that affects a product developed by Fusionpbx — matched by CVE ID, not by vendor name.