VYPR

Phpipam

by Phpipam

Source repositories

CVEs (54)

  • CVE-2019-16692CriSep 22, 2019
    risk 0.68cvss 9.8epss 0.10

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

  • CVE-2019-16693CriSep 22, 2019
    risk 0.67cvss 9.8epss 0.04

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

  • CVE-2022-41443CriOct 3, 2022
    risk 0.64cvss 9.8epss 0.01

    phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

  • CVE-2019-16696CriSep 22, 2019
    risk 0.64cvss 9.8epss 0.02

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.

  • CVE-2019-16695CriSep 22, 2019
    risk 0.64cvss 9.8epss 0.02

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.

  • CVE-2019-16694CriSep 22, 2019
    risk 0.64cvss 9.8epss 0.02

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.

  • CVE-2020-7988HigMar 4, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old…

  • CVE-2022-23046HigJan 19, 2022
    risk 0.52cvss 7.2epss 0.25

    PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

  • CVE-2024-41357HigJul 26, 2024
    risk 0.49cvss 7.1epss 0.01

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

  • CVE-2024-41354HigJul 26, 2024
    risk 0.46cvss 7.1epss 0.00

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php

  • CVE-2024-41353HigJul 26, 2024
    risk 0.46cvss 7.1epss 0.00

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php

  • CVE-2023-24657MedMar 8, 2023
    risk 0.43cvss 6.1epss 0.04

    phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.

  • CVE-2023-1211HigMar 7, 2023
    risk 0.43cvss 7.2epss 0.03

    SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.

  • CVE-2024-41355MedJul 26, 2024
    risk 0.42cvss 6.5epss 0.00

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

  • CVE-2025-61078MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.

  • CVE-2021-35438MedJun 23, 2021
    risk 0.40cvss 6.1epss 0.01

    phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.

  • CVE-2018-10329MedApr 24, 2018
    risk 0.40cvss 6.1epss 0.01

    app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.

  • CVE-2017-6481MedMar 5, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in…

  • CVE-2024-41358MedAug 29, 2024
    risk 0.36cvss 6.1epss 0.02

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

  • CVE-2017-15640MedApr 21, 2018
    risk 0.35cvss 5.4epss 0.01

    app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.

Page 1 of 3