Products: 7
    Vulnerabilities: 34
    Known Exploited: 0
    6
    Critical Level Threats
    10
    High Level Threats
    18
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-27362

    3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability

    Last Modified: Aug 13, 2025
    Published: May 03, 2024

    CVE-2023-49954

    The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.

    Last Modified: Apr 23, 2025
    Published: Dec 25, 2023

    CVE-2022-48483

    3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue exists because of an incomplete fix for CVE-2022-28005.

    Last Modified: Jan 30, 2025
    Published: May 02, 2023

    CVE-2022-48482

    3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

    Last Modified: Jan 30, 2025
    Published: May 02, 2023

    CVE-2023-29059

    3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.

    Last Modified: May 05, 2025
    Published: Mar 30, 2023
    Items Per Page