CVE Tools

Fusionpbx

42 CVEs tracked since 2019. Since Oct 2019, none of them reached CISA KEV.

Fusionpbx CVEs per month

Oct 2019 to Nov 2021. Point at a month, or focus the strip and use the arrow keys.
Fusionpbx CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-10260
2019-1170
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-0550
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-1140

Products

The products that kept showing up in Fusionpbx's monthly top three, with their CVEs summed over those months.

  1. Fusionpbx424 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Fusionpbx.

  1. CVE-2024-24539FusionPBX before 5.2.0 does not validate a session.5.3
  2. CVE-2024-23387FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script m...4.8
  3. CVE-2022-35153FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.9.8
  4. CVE-2021-37524Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.6.1
  5. CVE-2022-28055Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.9.8
  6. CVE-2021-43403An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log ...6.5
  7. CVE-2021-43405An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).8.8
  8. CVE-2021-43406An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).8.8
  9. CVE-2021-43404An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters.8.8
  10. CVE-2020-21057Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.8.1
  11. CVE-2020-21056Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.4.3
  12. CVE-2020-21055A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\fil...6.5
  13. CVE-2020-21054Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.6.1
  14. CVE-2020-21053Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\de...6.1
  15. CVE-2019-19384A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.6.1

The record

Peak rank
#25 in Oct 2019
Busiest month shown
Oct 2019, 26 CVEs
Months with a KEV entry
0 since Oct 2019
Monthly snapshots
4 since 2019
Fusionpbx's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store