VYPR

Switchvox SMB Edition

by Freepbx

CVEs (4)

  • CVE-2026-9586CriKEVJul 17, 2026
    risk 0.76cvss 9.8epss 0.12

    An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization…

  • CVE-2026-9588HigJul 17, 2026
    risk 0.00cvss epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated…

  • CVE-2026-9587HigJul 17, 2026
    risk 0.00cvss epss 0.00

    An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying…

  • CVE-2026-9585HigJul 17, 2026
    risk 0.00cvss epss 0.01

    An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied…