FreePBX Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for FreePBX products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
2
Beyond CISA KEV
2
Sensor Observed
0
Virtual Patch Available
0
FreePBX KEVs Added by Year
4 FreePBX KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-64328
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection |
filestore | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE |
endpoint | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-45461
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute... |
Rest Phone Apps | High | Not in CISA | 22 Dec 2021 |
|
CVE-2014-7235
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before... |
ARI Framework module/Asterisk Recording Interface (ARI) | High | Not in CISA | 07 Oct 2014 |
Common Vulnerability Classes (CWE)
- CWE-288 — Authentication Bypass Using an Alternate Path or Channel 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology