VYPR

Phpipam

by Phpipam

Source repositories

CVEs (54)

  • CVE-2026-4189MedMar 16, 2026
    risk 0.31cvss 4.7epss 0.00

    A weakness has been identified in phpipam up to 1.7.4. The impacted element is an unknown function of the file app/admin/sections/edit-result.php of the component Section Handler. Executing a manipulation of the argument subnetOrdering can lead to sql injection. The attack may…

  • CVE-2024-41356MedJul 26, 2024
    risk 0.31cvss 4.7epss 0.00

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.

  • CVE-2022-23045MedJan 19, 2022
    risk 0.31cvss 4.8epss 0.01

    PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.

  • CVE-2020-13225MedMay 20, 2020
    risk 0.31cvss 4.8epss 0.01

    phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.

  • CVE-2018-1000860MedDec 20, 2018
    risk 0.31cvss 4.7epss 0.01

    phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie is copied into an HTML tag on the login page encapsulated in single quotes. Editing the value of the cookie to r5zkh'>quqtl…

  • CVE-2025-60912LowDec 8, 2025
    risk 0.21cvss 3.3epss 0.00

    phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP…

  • CVE-2023-4965LowSep 14, 2023
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The…

  • CVE-2023-0678MedFeb 4, 2023
    risk 0.03cvss 5.3epss 0.37

    Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

  • CVE-2026-12194LowJul 4, 2026
    risk 0.00cvss epss 0.00

    PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.

  • CVE-2024-55093MedMar 31, 2025
    risk 0.00cvss 5.4epss 0.00

    phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.

  • CVE-2024-10727MedMar 20, 2025
    risk 0.00cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner. This allows an…

  • CVE-2024-10725MedMar 20, 2025
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs…

  • CVE-2024-10724MedMar 20, 2025
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version…

  • CVE-2024-10723MedMar 20, 2025
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field.…

  • CVE-2024-10722MedMar 20, 2025
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can lead to data theft, account…

  • CVE-2024-10721MedMar 20, 2025
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which can be executed in the context of other users who view the affected page. The issue…

  • CVE-2024-10720MedMar 20, 2025
    risk 0.00cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device Management' section under 'Administration' where an attacker can inject malicious scripts into the 'Name' and 'Description' fields when adding a new…

  • CVE-2024-10719MedMar 20, 2025
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerability allows an attacker to inject malicious scripts via the 'option' parameter in the POST request to…

  • CVE-2024-10718HigMar 20, 2025
    risk 0.00cvss 7.5epss 0.00

    In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

  • CVE-2024-0787MedNov 15, 2024
    risk 0.00cvss 5.9epss 0.00

    phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines 1044 and 1045, where the…