FusionPBX records
52 published records for vendor fusionpbx.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 1.9%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')32
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
52 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2019-11409Weaponized | app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of fusionpbx · fusionpbx · CWE-78 | High8.8 | — | 87.5% | Jun 17, 2019 |
46Plan | CVE-2021-43405Proof of concept | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | High8.8 | — | 35.6% | Nov 5, 2021 |
40Plan | CVE-2022-35153No exploit | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.fusionpbx · fusionpbx · CWE-116 | Critical9.8 | — | 1.8% | Aug 18, 2022 |
39Monitor | CVE-2019-15029Proof of concept | FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (whicfusionpbx · fusionpbx · CWE-78 | High8.8 | — | 12.3% | Sep 5, 2019 |
39Monitor | CVE-2022-28055No exploit | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.fusionpbx · fusionpbx · CWE-78 | Critical9.8 | — | 1.5% | May 3, 2022 |
36Monitor | CVE-2019-16964No exploit | app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lafusionpbx · fusionpbx · CWE-78 | High8.8 | — | 2.0% | Oct 21, 2019 |
35Monitor | CVE-2019-16980No exploit | In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an ufusionpbx · fusionpbx · CWE-89 | High8.8 | — | 1.2% | Oct 21, 2019 |
35Monitor | CVE-2021-43404No exploit | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | High8.8 | — | 1.0% | Nov 5, 2021 |
35Monitor | CVE-2021-43406No exploit | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx · CWE-20 | High8.8 | — | 1.0% | Nov 5, 2021 |
32Monitor | CVE-2020-21057No exploit | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder vafusionpbx · fusionpbx · CWE-22 | High8.1 | — | 1.5% | May 20, 2021 |
29Monitor | CVE-2019-11410No exploit | app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validatiofusionpbx · fusionpbx · CWE-78 | High7.2 | — | 3.4% | Jun 17, 2019 |
29Monitor | CVE-2019-16965No exploit | resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows aufusionpbx · fusionpbx · CWE-78 | High7.2 | — | 3.0% | Oct 21, 2019 |
28Monitor | CVE-2019-11407No exploit | app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due tofusionpbx · fusionpbx · CWE-200 | High7.2 | — | 1.5% | Jun 17, 2019 |
26Monitor | CVE-2019-11408Proof of concept | XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arfusionpbx · fusionpbx · CWE-79 | Medium6.1 | — | 6.9% | Jun 17, 2019 |
26Monitor | CVE-2019-16986No exploit | In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname anfusionpbx · fusionpbx · CWE-22 | Medium6.5 | — | 1.4% | Oct 21, 2019 |
26Monitor | CVE-2019-16990No exploit | In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takesfusionpbx · fusionpbx · CWE-22 | Medium6.5 | — | 1.3% | Oct 21, 2019 |
26Monitor | CVE-2020-21055No exploit | A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2fusionpbx · fusionpbx · CWE-22 | Medium6.5 | — | 1.2% | May 20, 2021 |
26Monitor | CVE-2019-16985No exploit | In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 dfusionpbx · fusionpbx · CWE-22 | Medium6.5 | — | 1.1% | Oct 21, 2019 |
26Monitor | CVE-2021-43403No exploit | An issue was discovered in FusionPBX before 4.5.30.fusionpbx · fusionpbx | Medium6.5 | — | 0.9% | Sep 28, 2022 |
24Monitor | CVE-2019-19387No exploit | A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrfusionpbx · fusionpbx · CWE-79 | Medium6.1 | — | 0.9% | Nov 28, 2019 |
24Monitor | CVE-2019-19386No exploit | A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackersfusionpbx · fusionpbx · CWE-79 | Medium6.1 | — | 0.9% | Nov 28, 2019 |
24Monitor | CVE-2019-19366No exploit | A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary fusionpbx · fusionpbx · CWE-79 | Medium6.1 | — | 0.9% | Nov 27, 2019 |
24Monitor | CVE-2019-19367No exploit | A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scripfusionpbx · fusionpbx · CWE-79 | Medium6.1 | — | 0.9% | Nov 27, 2019 |
24Monitor | CVE-2019-19384No exploit | A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scfusionpbx · fusionpbx · CWE-79 | Medium6.1 | — | 0.9% | Nov 28, 2019 |
24Monitor | CVE-2019-19385No exploit | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary webfusionpbx · fusionpbx · CWE-79 | Medium6.1 | — | 0.9% | Nov 28, 2019 |
- CVE-2019-1140961This week
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of
HighCVSS 8.8WeaponizedEPSS 87%fusionpbx · fusionpbxJun 17, 2019
- CVE-2021-4340546Plan
An issue was discovered in FusionPBX before 4.5.30.
HighCVSS 8.8Proof of conceptEPSS 36%fusionpbx · fusionpbxNov 5, 2021
- CVE-2022-3515340Plan
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
CriticalCVSS 9.8No exploitEPSS 2%fusionpbx · fusionpbxAug 18, 2022
- CVE-2019-1502939Monitor
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (whic
HighCVSS 8.8Proof of conceptEPSS 12%fusionpbx · fusionpbxSep 5, 2019
- CVE-2022-2805539Monitor
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
CriticalCVSS 9.8No exploitEPSS 2%fusionpbx · fusionpbxMay 3, 2022
- CVE-2019-1696436Monitor
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a la
HighCVSS 8.8No exploitEPSS 2%fusionpbx · fusionpbxOct 21, 2019
- CVE-2019-1698035Monitor
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an u
HighCVSS 8.8No exploitEPSS 1%fusionpbx · fusionpbxOct 21, 2019
- CVE-2021-4340435Monitor
An issue was discovered in FusionPBX before 4.5.30.
HighCVSS 8.8No exploitEPSS 1%fusionpbx · fusionpbxNov 5, 2021
- CVE-2021-4340635Monitor
An issue was discovered in FusionPBX before 4.5.30.
HighCVSS 8.8No exploitEPSS 1%fusionpbx · fusionpbxNov 5, 2021
- CVE-2020-2105732Monitor
Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder va
HighCVSS 8.1No exploitEPSS 2%fusionpbx · fusionpbxMay 20, 2021
- CVE-2019-1141029Monitor
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validatio
HighCVSS 7.2No exploitEPSS 3%fusionpbx · fusionpbxJun 17, 2019
- CVE-2019-1696529Monitor
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows au
HighCVSS 7.2No exploitEPSS 3%fusionpbx · fusionpbxOct 21, 2019
- CVE-2019-1140728Monitor
app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to
HighCVSS 7.2No exploitEPSS 2%fusionpbx · fusionpbxJun 17, 2019
- CVE-2019-1140826Monitor
XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject ar
MediumCVSS 6.1Proof of conceptEPSS 7%fusionpbx · fusionpbxJun 17, 2019
- CVE-2019-1698626Monitor
In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname an
MediumCVSS 6.5No exploitEPSS 1%fusionpbx · fusionpbxOct 21, 2019
- CVE-2019-1699026Monitor
In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes
MediumCVSS 6.5No exploitEPSS 1%fusionpbx · fusionpbxOct 21, 2019
- CVE-2020-2105526Monitor
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2
MediumCVSS 6.5No exploitEPSS 1%fusionpbx · fusionpbxMay 20, 2021
- CVE-2019-1698526Monitor
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 d
MediumCVSS 6.5No exploitEPSS 1%fusionpbx · fusionpbxOct 21, 2019
- CVE-2021-4340326Monitor
An issue was discovered in FusionPBX before 4.5.30.
MediumCVSS 6.5No exploitEPSS 1%fusionpbx · fusionpbxSep 28, 2022
- CVE-2019-1938724Monitor
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitr
MediumCVSS 6.1No exploitEPSS 1%fusionpbx · fusionpbxNov 28, 2019
- CVE-2019-1938624Monitor
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers
MediumCVSS 6.1No exploitEPSS 1%fusionpbx · fusionpbxNov 28, 2019
- CVE-2019-1936624Monitor
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary
MediumCVSS 6.1No exploitEPSS 1%fusionpbx · fusionpbxNov 27, 2019
- CVE-2019-1936724Monitor
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web scrip
MediumCVSS 6.1No exploitEPSS 1%fusionpbx · fusionpbxNov 27, 2019
- CVE-2019-1938424Monitor
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web sc
MediumCVSS 6.1No exploitEPSS 1%fusionpbx · fusionpbxNov 28, 2019
- CVE-2019-1938524Monitor
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web
MediumCVSS 6.1No exploitEPSS 1%fusionpbx · fusionpbxNov 28, 2019