|
:green_circle: Authenticated low-privilege UCP user can modify contacts of other users
|
|
6
|
81
|
October 1, 2026
|
|
:green_circle: Authenticated privilege escalation in API module via SQL injection in Pinsets
|
|
0
|
30
|
September 29, 2026
|
|
:orange_circle: Authenticated low-privilege UCP user can read full database via SQL injection
|
|
0
|
23
|
September 29, 2026
|
|
:green_circle: Authenticated admin SQL injection via SIPSTATION module
|
|
0
|
22
|
September 29, 2026
|
|
Asterisk updated to 20.21.0, 22.11.0 and 23.5.0
|
|
5
|
177
|
September 28, 2026
|
|
Virtual Private Question
|
|
9
|
210
|
September 27, 2026
|
|
:green_circle: Authenticated Root OS Command Injection in Backup GraphQL restoreBackup
|
|
0
|
35
|
September 17, 2026
|
|
:green_circle: Authenticated Second-Order OS Command Execution in FreePBX Recordings via Dialplan Injection
|
|
0
|
37
|
September 17, 2026
|
|
:green_circle: Authenticated RCE in UCP via AMI
|
|
0
|
40
|
September 17, 2026
|
|
:green_circle: Authenticated admin can read any file via call recording report
|
|
0
|
35
|
September 17, 2026
|
|
:orange_circle: Authenticated RCE via unsafe unserialize in backup restore
|
|
0
|
32
|
September 17, 2026
|
|
:orange_circle: Unauthenticated inbound CallerID becomes stored XSS in CEL Reports
|
|
0
|
45
|
September 17, 2026
|
|
:green_circle: Authenticated but Broken access control in the FreePBX framework GraphQL API
|
|
1
|
51
|
September 30, 2026
|
|
:green_circle: Authenticated admin with limited privileges can escalate perms via Framework BMO AJAX dispatcher
|
|
1
|
45
|
September 23, 2026
|
|
:orange_circle: Authenticated RCE in FindMeFollowMe function of Sangoma Connect
|
|
1
|
49
|
September 23, 2026
|
|
:green_circle: Authenticated Backup Metadata Hooks Execution Bypass
|
|
1
|
40
|
September 23, 2026
|
|
:green_circle: Authenticated Backup GraphQL Restore Filename Command Injection
|
|
1
|
43
|
September 23, 2026
|
|
:orange_circle: Unauthenticated RCE via SQL injection in Sangoma Connect RT API login
|
|
1
|
74
|
September 20, 2026
|
|
:orange_circle: Unauthenticated Missing Authorization in FreePBX UCP allows reset/overwrite of any user's dashboard templates
|
|
1
|
70
|
September 20, 2026
|
|
Updated security repo README
|
|
1
|
68
|
September 19, 2026
|
|
[SURVEY] Limiting access to Asterisk CLI from the GUI
|
|
7
|
271
|
August 28, 2026
|
|
AI Slop and Security noise
|
|
5
|
242
|
August 22, 2026
|
|
:orange_circle: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
|
|
3
|
138
|
August 16, 2026
|
|
:red_circle: Unauthenticated remote code execution in FreePBX UCP via socket.io namespace auth bypass and AMI action injection
|
|
4
|
242
|
August 16, 2026
|
|
Asterisk versions updated with asterisk-version-switch
|
|
1
|
95
|
August 15, 2026
|
|
:green_circle: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
|
|
1
|
53
|
August 15, 2026
|
|
:green_circle: Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files
|
|
1
|
52
|
August 15, 2026
|
|
:green_circle: Authenticated TTS AGI Command Injection Through TTS Name
|
|
1
|
57
|
August 15, 2026
|
|
Expired softphone license changes
|
|
2
|
319
|
August 12, 2026
|
|
Sangoma Silently Breaks S-Series Redirect — Manufacturer Neglect and Planned Obsolescence at Its Finest
|
|
66
|
1141
|
August 12, 2026
|