fusionpbx CVE Vulnerabilities & Metrics

Focus on fusionpbx vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About fusionpbx Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with fusionpbx. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total fusionpbx CVEs: 51
Earliest CVE date: 17 Jun 2019, 18:15 UTC
Latest CVE date: 19 Jan 2024, 04:15 UTC

Latest CVE reference: CVE-2024-23387

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical fusionpbx CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.77

Max CVSS: 9.0

Critical CVEs (≥9): 4

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 42
7.0-8.9 2
9.0-10.0 4

CVSS Distribution Chart

Top 5 Highest CVSS fusionpbx CVEs

These are the five CVEs with the highest CVSS scores for fusionpbx, sorted by severity first and recency.

All CVEs for fusionpbx

CVE-2024-23387 fusionpbx vulnerability CVSS: 0 19 Jan 2024, 04:15 UTC

FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.

CVE-2021-43403 fusionpbx vulnerability CVSS: 0 29 Sep 2022, 03:15 UTC

An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to choose an arbitrary filename for download (i.e., not necessarily freeswitch.log in the intended directory).

CVE-2022-35153 fusionpbx vulnerability CVSS: 0 18 Aug 2022, 05:15 UTC

FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

CVE-2021-37524 fusionpbx vulnerability CVSS: 4.3 01 Jul 2022, 18:15 UTC

Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web script or HTML via an unsanitized "path" parameter in resources/login.php.

CVE-2022-28055 fusionpbx vulnerability CVSS: 7.5 04 May 2022, 03:15 UTC

Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.

CVE-2021-43406 fusionpbx vulnerability CVSS: 6.5 05 Nov 2021, 18:15 UTC

An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained to preset values).

CVE-2021-43405 fusionpbx vulnerability CVSS: 6.5 05 Nov 2021, 18:15 UTC

An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).

CVE-2021-43404 fusionpbx vulnerability CVSS: 6.5 05 Nov 2021, 18:15 UTC

An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters.

CVE-2020-21057 fusionpbx vulnerability CVSS: 5.5 20 May 2021, 16:15 UTC

Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php.

CVE-2020-21056 fusionpbx vulnerability CVSS: 4.0 20 May 2021, 16:15 UTC

Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.

CVE-2020-21055 fusionpbx vulnerability CVSS: 4.0 20 May 2021, 16:15 UTC

A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php.

CVE-2020-21054 fusionpbx vulnerability CVSS: 4.3 20 May 2021, 16:15 UTC

Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.

CVE-2020-21053 fusionpbx vulnerability CVSS: 4.3 20 May 2021, 15:15 UTC

Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php.

CVE-2019-19388 fusionpbx vulnerability CVSS: 4.3 29 Nov 2019, 00:15 UTC

A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.

CVE-2019-19387 fusionpbx vulnerability CVSS: 4.3 29 Nov 2019, 00:15 UTC

A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.

CVE-2019-19386 fusionpbx vulnerability CVSS: 4.3 29 Nov 2019, 00:15 UTC

A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.

CVE-2019-19385 fusionpbx vulnerability CVSS: 4.3 29 Nov 2019, 00:15 UTC

A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.

CVE-2019-19384 fusionpbx vulnerability CVSS: 4.3 29 Nov 2019, 00:15 UTC

A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.

CVE-2019-19367 fusionpbx vulnerability CVSS: 4.3 27 Nov 2019, 20:15 UTC

A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVE-2019-19366 fusionpbx vulnerability CVSS: 4.3 27 Nov 2019, 20:15 UTC

A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.

CVE-2019-16977 fusionpbx vulnerability CVSS: 4.3 23 Oct 2019, 17:15 UTC

In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16975 fusionpbx vulnerability CVSS: 4.3 23 Oct 2019, 16:15 UTC

In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16976 fusionpbx vulnerability CVSS: 4.3 23 Oct 2019, 15:15 UTC

In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

CVE-2019-16973 fusionpbx vulnerability CVSS: 4.3 22 Oct 2019, 22:15 UTC

In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16972 fusionpbx vulnerability CVSS: 4.3 22 Oct 2019, 22:15 UTC

In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16971 fusionpbx vulnerability CVSS: 4.3 22 Oct 2019, 22:15 UTC

In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

CVE-2019-16974 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 21:15 UTC

In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16969 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 21:15 UTC

In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16970 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 20:15 UTC

In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16968 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 20:15 UTC

An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.

CVE-2019-16965 fusionpbx vulnerability CVSS: 9.0 21 Oct 2019, 19:15 UTC

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

CVE-2019-16964 fusionpbx vulnerability CVSS: 9.0 21 Oct 2019, 19:15 UTC

app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) to execute any commands on the host as www-data.

CVE-2019-16991 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16989 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16988 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

CVE-2019-16987 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16986 fusionpbx vulnerability CVSS: 4.0 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)

CVE-2019-16985 fusionpbx vulnerability CVSS: 8.5 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.

CVE-2019-16984 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.

CVE-2019-16983 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.

CVE-2019-16982 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16981 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 16:15 UTC

In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

CVE-2019-16990 fusionpbx vulnerability CVSS: 4.0 21 Oct 2019, 15:15 UTC

In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any pathname (base64 encoded) and allows a download of it.

CVE-2019-16980 fusionpbx vulnerability CVSS: 6.5 21 Oct 2019, 15:15 UTC

In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection.

CVE-2019-16979 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 15:15 UTC

In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVE-2019-16978 fusionpbx vulnerability CVSS: 4.3 21 Oct 2019, 15:15 UTC

In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

CVE-2019-15029 fusionpbx vulnerability CVSS: 9.0 05 Sep 2019, 21:15 UTC

FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To trigger the command, one needs to call the services.php file via a GET request with the service id followed by the parameter a=start to execute the stored command.

CVE-2019-11410 fusionpbx vulnerability CVSS: 9.0 17 Jun 2019, 19:15 UTC

app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.

CVE-2019-11409 fusionpbx vulnerability CVSS: 6.5 17 Jun 2019, 19:15 UTC

app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. This can further lead to remote code execution when combined with an XSS vulnerability also present in the FusionPBX Operator Panel module.

CVE-2019-11408 fusionpbx vulnerability CVSS: 4.3 17 Jun 2019, 18:15 UTC

XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted caller ID number. This can further lead to remote code execution by chaining this vulnerability with a command injection vulnerability also present in FusionPBX.

CVE-2019-11407 fusionpbx vulnerability CVSS: 4.0 17 Jun 2019, 18:15 UTC

app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.