FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sangoma
Sangoma freepbx |
|
| CPEs | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sangoma
Sangoma freepbx |
|
| Metrics |
cvssV3_1
|
Fri, 06 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freepbx
Freepbx security-reporting |
|
| Vendors & Products |
Freepbx
Freepbx security-reporting |
Thu, 05 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5. | |
| Title | FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-05T18:24:50.528Z
Updated: 2026-03-06T16:10:51.331Z
Reserved: 2026-02-26T01:52:58.735Z
Link: CVE-2026-28284
Updated: 2026-03-06T15:58:34.124Z
Status : Analyzed
Published: 2026-03-05T19:16:14.867
Modified: 2026-03-06T18:32:58.330
Link: CVE-2026-28284
No data.