FreePBX Vulnerabilities and Affected Products
Vulnerabilities associated with tts.
Products
Clear product- security-reporting9 vulnerabilities
- framework5 vulnerabilities
- endpoint4 vulnerabilities
- api3 vulnerabilities
- endpointman2 vulnerabilities
- FreePBX2 vulnerabilities
- tts2 vulnerabilities
- arimanager1 vulnerability
- backup1 vulnerability
- cdr1 vulnerability
- contactmanager1 vulnerability
- core1 vulnerability
- endpoint_manager1 vulnerability
- filestore1 vulnerability
- FreePBX Framework1 vulnerability
- missedcall1 vulnerability
- music1 vulnerability
- restapps1 vulnerability
- ucp1 vulnerability
- voicemail1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-73660HIGH | FreePBX: Authenticated TTS AGI Command Injection Through TTS NameFreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames inside agi-bin/propolys-tts.agi. The TTS destination name reaches a raw shell-command execution path, allowing arbitrary operating-system command execution as the asterisk service user. This issue is fixed in… CWE-78Aug 13, 2026 | CVSS7.5v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67736HIGH | Authenticated SQL Injection in FreePBX tts (Text To Speech) moduleThe FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 are vulnerable to SQL injection by authenticated users with administrator access. Authenticated users with administrative access to the Administrator Control Panel (ACP) can leverage this SQL injection vulnerability to extract sensitive information from the database and execute code on the system as the `asterisk` user with chaine… CWE-89Dec 16, 2025 | CVSS8.6v4.0 | EPSS6.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |