framework
FreePBX- Product type
- Other
- Catalog vulnerabilities
- 5
Severity across 5 analyzed records
Verify to analyze this security profile
en
As of 09/20/2026, within CyStack's analyzed data, framework has 1 security vulnerability published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of framework and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-73661FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup | Exploitation statusNot known exploited | FixYes | Published08/13/2026 | SeverityHigh |
CVE-2025-67722Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation | Exploitation statusNot known exploited | FixNot confirmed | Published12/16/2025 | SeverityMedium |
CVE-2025-66039FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityCritical |
CVE-2025-59056FreePBX vulnerable to unauthenticated Denial of Service | Exploitation statusNot known exploited | FixYes | Published09/15/2025 | SeverityMedium |
CVE-2025-55211FreePBX Post-Authenticated Command Injection | Exploitation statusNot known exploited | FixYes | Published09/15/2025 | SeverityMedium |