FreePBX Vulnerabilities and Affected Products
Vulnerabilities associated with FreePBX.
Products
Clear product- security-reporting9 vulnerabilities
- framework5 vulnerabilities
- endpoint4 vulnerabilities
- api3 vulnerabilities
- endpointman2 vulnerabilities
- FreePBX2 vulnerabilities
- tts2 vulnerabilities
- arimanager1 vulnerability
- backup1 vulnerability
- cdr1 vulnerability
- contactmanager1 vulnerability
- core1 vulnerability
- endpoint_manager1 vulnerability
- filestore1 vulnerability
- FreePBX Framework1 vulnerability
- missedcall1 vulnerability
- music1 vulnerability
- restapps1 vulnerability
- ucp1 vulnerability
- voicemail1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-58294HIGH | FreePBX 16 Authenticated Remote Code Execution via API ModuleFreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access. CWE-78Dec 11, 2025 | CVSS8.7v4.0 | EPSS3.62% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
freepbx FreePBX Improper Control of Generation of Code ('Code Injection')htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserialize function, as exploited in the wild in September 2014. CWE-94Oct 7, 2014 | CVSS10.0v2.0 | EPSS43.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |