VYPR

Completepbx

by Xorcom

CVEs (4)

  • CVE-2025-30004HigMar 31, 2025
    risk 0.61cvss 8.8epss 0.04

    Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user. This issue affects CompletePBX: all versions up to and prior to 5.2.35

  • CVE-2025-30005HigMar 31, 2025
    risk 0.57cvss 8.3epss 0.02

    Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to…

  • CVE-2025-2292MedMar 31, 2025
    risk 0.45cvss 6.5epss 0.02

    Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.This issue affects CompletePBX: through 5.2.35.

  • CVE-2025-30006MedMar 31, 2025
    risk 0.40cvss 6.1epss 0.00

    Xorcom CompletePBX is vulnerable to a reflected cross-site scripting (XSS) in the administrative control panel. This issue affects CompletePBX: all versions up to and prior to 5.2.35