Vitalpbx is a unified communications and IP-PBX platform where the observed vulnerability pattern centers on web-application security issues including cross-site request forgery, improper access control, cross-site scripting, and weak random-value generation. These weakness classes reflect the authentication and session-management demands of a browser-facing administrative interface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vitalpbx over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0486MEDIUM VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. This is possible because the application i | Apr 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-0480HIGH VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. This is possible because the application is vulnerable to CSRF. | Apr 4, 2023 | 8.8 | 21 | NO | NO |
CVE-2022-29330MEDIUM Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails | Jun 24, 2022 | 4.9 | 21 | NO | NO |
CVE-2024-24386HIGH An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder. | Feb 15, 2024 | 7.2 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vitalpbx.
Media articles that mention a CVE ID that affects a product developed by Vitalpbx — matched by CVE ID, not by vendor name.