Xorcom develops CompletePBX, a unified communications platform, with a vulnerability profile centered on web-application and system-interaction flaws including path traversal, cross-site scripting, and OS command injection. These weakness classes reflect the product's role as a networked, browser-accessible service handling user input and system configuration; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xorcom over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30004HIGH Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user.
| Mar 31, 2025 | 8.8 | 40 | NO | YES |
CVE-2025-30005HIGH Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in | Mar 31, 2025 | 8.3 | 37 | NO | YES |
CVE-2025-2292MEDIUM Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.This issue affects CompletePBX: thro | Mar 31, 2025 | 6.5 | 32 | NO | YES |
CVE-2025-30006MEDIUM Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel.
This issue affects CompletePBX: all versions up to and prior to | Mar 31, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xorcom.
Media articles that mention a CVE ID that affects a product developed by Xorcom — matched by CVE ID, not by vendor name.