Phpipam
by Phpipam
Source repositories
CVEs (54)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16692 | Cri | 0.68 | 9.8 | 0.10 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. | ||
| CVE-2019-16693 | Cri | 0.67 | 9.8 | 0.04 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | ||
| CVE-2022-41443 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2022 | phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php. | ||
| CVE-2019-16696 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used. | ||
| CVE-2019-16695 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used. | ||
| CVE-2019-16694 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used. | ||
| CVE-2020-7988 | Hig | 0.57 | 8.8 | 0.01 | Mar 4, 2020 | An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old… | ||
| CVE-2022-23046 | Hig | 0.52 | 7.2 | 0.25 | Jan 19, 2022 | PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | ||
| CVE-2024-41357 | Hig | 0.49 | 7.1 | 0.01 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. | ||
| CVE-2024-41354 | Hig | 0.46 | 7.1 | 0.00 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php | ||
| CVE-2024-41353 | Hig | 0.46 | 7.1 | 0.00 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php | ||
| CVE-2023-24657 | Med | 0.43 | 6.1 | 0.04 | Mar 8, 2023 | phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. | ||
| CVE-2023-1211 | Hig | 0.43 | 7.2 | 0.03 | Mar 7, 2023 | SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2. | ||
| CVE-2024-41355 | Med | 0.42 | 6.5 | 0.00 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php. | ||
| CVE-2025-61078 | Med | 0.40 | 6.1 | 0.00 | Dec 9, 2025 | Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint. | ||
| CVE-2021-35438 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2021 | phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator. | ||
| CVE-2018-10329 | Med | 0.40 | 6.1 | 0.01 | Apr 24, 2018 | app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter. | ||
| CVE-2017-6481 | Med | 0.40 | 6.1 | 0.01 | Mar 5, 2017 | Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in… | ||
| CVE-2024-41358 | Med | 0.36 | 6.1 | 0.02 | Aug 29, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. | ||
| CVE-2017-15640 | Med | 0.35 | 5.4 | 0.01 | Apr 21, 2018 | app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter. |
- risk 0.68cvss 9.8epss 0.10
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
- risk 0.67cvss 9.8epss 0.04
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.01
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old…
- risk 0.52cvss 7.2epss 0.25
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
- risk 0.49cvss 7.1epss 0.01
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
- risk 0.46cvss 7.1epss 0.00
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
- risk 0.46cvss 7.1epss 0.00
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
- risk 0.43cvss 6.1epss 0.04
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
- risk 0.43cvss 7.2epss 0.03
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
- risk 0.42cvss 6.5epss 0.00
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.
- risk 0.40cvss 6.1epss 0.01
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
- risk 0.40cvss 6.1epss 0.01
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.
- risk 0.40cvss 6.1epss 0.01
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in…
- risk 0.36cvss 6.1epss 0.02
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
- risk 0.35cvss 5.4epss 0.01
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.
Page 1 of 3