Known Vulnerabilities for Sangoma by Vendor
Listed below are 7 of the newest known vulnerabilities associated with "Sangoma" by "Vendor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45362 json | Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file. | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-9588 json | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail n... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-9587 json | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file funct... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-9586 json | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint proces... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-9585 json | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (10... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2023-43336 json | Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control is... | Not Provided | 2023-11-02 | 2026-07-09 |
| CVE-2022-37325 json | In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to add... | Not Provided | 2022-12-05 | 2026-07-02 |