VYPR

Switchvox SMB Edition

by Freepbx

CVEs (3)

  • CVE-2026-9587Jul 17, 2026
    risk 0.00cvss epss 0.00

    An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying…

  • CVE-2026-9586Jul 17, 2026
    risk 0.00cvss epss 0.00

    An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization…

  • CVE-2026-9585Jul 17, 2026
    risk 0.00cvss epss 0.00

    An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied…