Vitalpbx

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-24386

    An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

    Last Modified: Sep 18, 2025
    Published: Feb 15, 2024

    CVE-2023-0480

    VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. This is possible because the application is vulnerable to CSRF.

    Last Modified: Feb 13, 2025
    Published: Apr 04, 2023

    CVE-2023-0486

    VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance's administrator account via a malicious link. This is possible because the application is vulnerable to XSS.

    Last Modified: Feb 13, 2025
    Published: Apr 04, 2023

    CVE-2022-29330

    Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2022
    Items Per Page
    Vitalpbx Vulnerabilities & Security CVEs | CVE-DB