Phpipam
Vendor:
First CVE: Aug 20, 2015 · Active for 10 years
52
Total CVEs
More Total CVEs than 98% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Phpipam over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2015
10 years ago
Most Recent CVE
Dec 9, 2025
227 days ago
CVE Severity & Scoring
Phpipam52 CVEs
69%
15%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network51 (98.1%)
Unknown1 (1.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (90.4%)
High4 (7.7%)
Unknown1 (1.9%)
User Interaction
None17 (32.7%)
Unknown1 (1.9%)
Required34 (65.4%)
Privileges Required
Low12 (23.1%)
High8 (15.4%)
None31 (59.6%)
Unknown1 (1.9%)
Top CVEs
Signals from CVEs in this product scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0678MEDIUM Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1. | Feb 4, 2023 | 5.3 | 50 | NO | YES |
CVE-2022-23046HIGH PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | Jan 19, 2022 | 7.2 | 48 | NO | YES |
CVE-2019-16692CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 47 | NO | YES |
CVE-2019-16693CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 42 | NO | YES |
CVE-2023-24657MEDIUM phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. | Mar 8, 2023 | 6.1 | 41 | NO | YES |
CVE-2023-0676MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1. | Feb 4, 2023 | 6.1 | 32 | NO | YES |
CVE-2022-41443CRITICAL phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php. | Oct 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-1000869CRITICAL phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, | Dec 20, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-16696CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-16695CRITICAL phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used. | Sep 22, 2019 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (52 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
5.8% of CVEs· 97th percentile
ExploitDB
7 CVEs
13.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (52 CVEs).
Media Mentions
Signals from CVEs in this product scope (52 CVEs).
Top CNAs Publishing CVEs For Phpipam
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.7.3 | 1 | 6.1 | 0.2% | 0 | 0 |
| 1.6 | 7 | 6.4 | 1.1% | 0 | 3 |
| 1.5.2 | 1 | 5.4 | 0.3% | 0 | 0 |
| 1.5.1 | 1 | 4.8 | 0.5% | 0 | 0 |
| 1.5.0 | 1 | 9.8 | 1.1% | 0 | 0 |
| 1.4.4 | 3 | 6.0 | 8.9% | 0 | 1 |
| 1.4.3 | 1 | 6.1 | 1.0% | 0 | 0 |
| 1.4 | 2 | 6.8 | 0.7% | 0 | 0 |
| 1.3.2 | 1 | 9.8 | 1.8% | 0 | 0 |
| 1.3.1 | 1 | 6.1 | 0.8% | 0 | 0 |
| 1.1.010 | 1 | 4.3 | 2.4% | 0 | 0 |