Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sangoma

First CVE: Apr 3, 2009Active for: 17 yearsTotal CVEs: 84
72.5
VTI Score
TOP TARGET

Sangoma develops a modestly represented but strategically prominent portfolio centered on FreePBX, Asterisk, and session border control products that serve telecommunications infrastructure and VoIP deployments worldwide. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the sensitivity of voice-communications platforms to both in-the-wild attack and proof-of-concept development. The exposure recurs across the Asterisk ecosystem and unified communications appliances through a durable set of input-handling and authentication weaknesses—cross-site scripting, SQL injection, OS command injection, path traversal, and improper authentication—that are characteristic of web-facing telephony management interfaces and protocol parsing layers. Defenders should treat updates to these core products as operationally critical given their role in call routing and session management; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
84
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
3.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sangoma over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2009
17 years ago
Most Recent CVE
May 29, 2026
56 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (84 CVEs).

84 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-64328HIGH
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrat
Nov 7, 20257.298YESYES
CVE-2025-57819CRITICAL
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenti
Aug 28, 20259.898YESYES
CVE-2019-19006CRITICAL
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
Nov 21, 20199.884YESNO
CVE-2012-4869HIGH
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter
Sep 6, 20127.578NOYES
CVE-2014-1903HIGH
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions
Feb 18, 20147.567NOYES
CVE-2014-7235HIGH
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to
Oct 7, 201410.059NOYES
CVE-2025-66039CRITICAL
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "w
Dec 9, 20259.851NOYES
CVE-2023-49294HIGH
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cer
Dec 14, 20237.543NONO
CVE-2026-46376CRITICAL
FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial templ
May 29, 20269.839NONO
CVE-2021-45461CRITICAL
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the
Dec 22, 20219.836NONO
View all 84 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products84 CVEs
39%
42%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (7.1%)
Network66 (78.6%)
Unknown12 (14.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low68 (81.0%)
High4 (4.8%)
Unknown12 (14.3%)
User Interaction
None56 (66.7%)
Unknown12 (14.3%)
Required16 (19.0%)
Privileges Required
Low26 (31.0%)
High13 (15.5%)
None33 (39.3%)
Unknown12 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (84 CVEs).

CISA KEV
3 CVEs
3.6% of CVEs· 99th percentile
Metasploit
5 CVEs
6.0% of CVEs· 98th percentile
Nuclei
2 CVEs
2.4% of CVEs· 95th percentile
ExploitDB
5 CVEs
6.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sangoma.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sangoma — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sangoma's Products

View all 7 CNAs →

Top CWEs