Phpipam is an open-source IP address management solution deployed across network infrastructure teams and hosting environments, presenting a focused but strategically exposed attack surface at the boundary between administrative interfaces and critical network metadata. Vulnerabilities affecting the product skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency to acquire public exploit code, reflecting both the sensitivity of IP asset data and the accessibility of administrative web interfaces. The exposure recurs consistently through web-application weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and authorization flaws, alongside cleartext transmission of sensitive data—patterns endemic to legacy administrative tools that manage valuable infrastructure assets without modern security primitives. Defenders should treat Phpipam instances as high-priority patching targets and restrict administrative access to trusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpipam over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0678MEDIUM Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1. | Feb 4, 2023 | 5.3 | 50 | NO | YES |
CVE-2022-23046HIGH PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | Jan 19, 2022 | 7.2 | 48 | NO | YES |
CVE-2019-16692CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 47 | NO | YES |
CVE-2019-16693CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 42 | NO | YES |
CVE-2023-24657MEDIUM phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. | Mar 8, 2023 | 6.1 | 41 | NO | YES |
CVE-2023-0676MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1. | Feb 4, 2023 | 6.1 | 32 | NO | YES |
CVE-2022-41443CRITICAL phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php. | Oct 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-1000869CRITICAL phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, | Dec 20, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-16696CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-16695CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpipam.
Media articles that mention a CVE ID that affects a product developed by Phpipam — matched by CVE ID, not by vendor name.