Phpipam

Vendor:

First CVE: Aug 20, 2015 · Active for 10 years

52
Total CVEs
More Total CVEs than 98% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Phpipam over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2015
10 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

CVE Severity & Scoring

Phpipam52 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network51 (98.1%)
Unknown1 (1.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (90.4%)
High4 (7.7%)
Unknown1 (1.9%)
User Interaction
None17 (32.7%)
Unknown1 (1.9%)
Required34 (65.4%)
Privileges Required
Low12 (23.1%)
High8 (15.4%)
None31 (59.6%)
Unknown1 (1.9%)

Top CVEs

Signals from CVEs in this product scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
Feb 4, 20235.350NOYES
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
Jan 19, 20227.248NOYES
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
Sep 22, 20199.847NOYES
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
Sep 22, 20199.842NOYES
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
Mar 8, 20236.141NOYES
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
Feb 4, 20236.132NOYES
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
Oct 3, 20229.831NONO
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user,
Dec 20, 20189.831NONO
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
Sep 22, 20199.830NONO
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
Sep 22, 20199.830NONO

Exploit Exposure

Signals from CVEs in this product scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
5.8% of CVEs· 97th percentile
ExploitDB
7 CVEs
13.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (52 CVEs).

Media Mentions

Signals from CVEs in this product scope (52 CVEs).

Top CNAs Publishing CVEs For Phpipam

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.7.316.10.2%00
1.676.41.1%03
1.5.215.40.3%00
1.5.114.80.5%00
1.5.019.81.1%00
1.4.436.08.9%01
1.4.316.11.0%00
1.426.80.7%00
1.3.219.81.8%00
1.3.116.10.8%00
1.1.01014.32.4%00