Phpipam
56 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Phpipam, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Phpipam CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 10 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 2 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 2 |
| 2026-09 | 1 |
Severity
How the 56 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical8
- High10
- Medium34
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Phpipam.
- CVE-2026-97818phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.8.6
- CVE-2026-67602phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache9.1
- CVE-2026-75105phpIPAM Temporary Subnet Share Information Disclosure via Address Parameter7.5
- CVE-2026-12194PHPIPAM Authenticated LFI—
- CVE-2025-61078Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instru...6.1
- CVE-2025-60912phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, a...3.3
- CVE-2024-55093phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.5.4
- CVE-2024-10721Store XSS in phpipam/phpipam5.4
- CVE-2024-10727Cross-Site Scripting (XSS) in phpipam/phpipam6.1
- CVE-2024-10720Stored Cross-site Scripting (XSS) in phpipam/phpipam6.1
- CVE-2024-10722Stored Cross-site Scripting (XSS) in phpipam/phpipam5.4
- CVE-2024-10719Stored Cross-site Scripting (XSS) in phpipam/phpipam5.4
- CVE-2024-10718Cookie without Secure attribute in phpipam/phpipam7.5
- CVE-2024-10724Stored XSS in IPV6 Section in phpipam/phpipam5.4
- CVE-2024-10723Stored XSS in phpipam/phpipam5.4
Product grouping is registry-driven, with AI assist and human review. How it works