FreePBX Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for FreePBX products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

2

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

FreePBX KEVs Added by Year

Loading...

4 FreePBX KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-64328

FreePBX Administration GUI is Vulnerable to Authenticated Command Injection

Confirmed In CISA 01 Jun 2026
CVE-2025-57819

FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE

Confirmed In CISA 01 Jun 2026
CVE-2021-45461

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute...

High Not in CISA 22 Dec 2021
CVE-2014-7235

htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before...

High Not in CISA 07 Oct 2014

Common Vulnerability Classes (CWE)

  • CWE-288 — Authentication Bypass Using an Alternate Path or Channel 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology