Known Vulnerabilities for products from Fusionpbx
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Fusionpbx".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-23387 json | 4.8 - MEDIUM | 2024-01-19 | 2024-01-25 | |
| CVE-2022-35153 json | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php. | 9.8 - CRITICAL | 2022-08-18 | 2023-08-08 |
| CVE-2022-28055 json | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function. | 9.8 - CRITICAL | 2022-05-04 | 2023-08-08 |
| CVE-2021-43406 json | An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to pre... | 8.8 - HIGH | 2021-11-05 | 2021-11-09 |
| CVE-2021-43405 json | An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be ... | 8.8 - HIGH | 2021-11-05 | 2023-08-08 |
| CVE-2021-43404 json | An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters. | 8.8 - HIGH | 2021-11-05 | 2023-08-08 |
| CVE-2021-43403 json | An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose a... | 6.5 - MEDIUM | 2022-09-29 | 2022-09-30 |
| CVE-2021-37524 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-07-01 | 2022-07-12 |
| CVE-2020-21057 json | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system vi... | 8.1 - HIGH | 2021-05-20 | 2021-05-25 |
| CVE-2020-21056 json | Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the f... | 4.3 - MEDIUM | 2021-05-20 | 2021-05-25 |
| CVE-2020-21055 json | A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the... | 6.5 - MEDIUM | 2021-05-20 | 2021-05-25 |
| CVE-2020-21054 json | Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or H... | 6.1 - MEDIUM | 2021-05-20 | 2021-05-25 |
| CVE-2020-21053 json | Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web scr... | 6.1 - MEDIUM | 2021-05-20 | 2021-05-25 |
| CVE-2019-19388 json | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attacke... | 6.1 - MEDIUM | 2019-11-29 | 2019-12-02 |
| CVE-2019-19387 json | A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers t... | 6.1 - MEDIUM | 2019-11-29 | 2019-12-02 |
| CVE-2019-19386 json | A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows r... | 6.1 - MEDIUM | 2019-11-29 | 2019-12-02 |
| CVE-2019-19385 json | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to injec... | 6.1 - MEDIUM | 2019-11-29 | 2019-12-02 |
| CVE-2019-19384 json | A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject a... | 6.1 - MEDIUM | 2019-11-29 | 2019-12-02 |
| CVE-2019-19367 json | A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbi... | 6.1 - MEDIUM | 2019-11-27 | 2019-12-04 |
| CVE-2019-19366 json | A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to in... | 6.1 - MEDIUM | 2019-11-27 | 2019-12-04 |
Known software with vulnerabilities from Fusionpbx
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Fusionpbx | Fusionpbx | 4.0.0 |