Phpipam
Products
1- 57 CVEs
Recent CVEs
57| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16692 | Cri | 0.68 | 9.8 | 0.10 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used. | ||
| CVE-2019-16693 | Cri | 0.67 | 9.8 | 0.04 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | ||
| CVE-2022-41443 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2022 | phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php. | ||
| CVE-2019-16696 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used. | ||
| CVE-2019-16695 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used. | ||
| CVE-2019-16694 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used. | ||
| CVE-2018-1000869 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2018 | phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This… | ||
| CVE-2020-7988 | Hig | 0.57 | 8.8 | 0.01 | Mar 4, 2020 | An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old… | ||
| CVE-2026-67602 | Cri | 0.52 | 9.1 | 0.01 | Aug 24, 2026 | phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched… | ||
| CVE-2022-23046 | Hig | 0.52 | 7.2 | 0.25 | Jan 19, 2022 | PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | ||
| CVE-2026-97818 | Hig | 0.49 | 8.6 | 0.00 | Sep 25, 2026 | phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. | ||
| CVE-2024-41357 | Hig | 0.49 | 7.1 | 0.01 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. | ||
| CVE-2024-41354 | Hig | 0.46 | 7.1 | 0.00 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php | ||
| CVE-2024-41353 | Hig | 0.46 | 7.1 | 0.00 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php | ||
| CVE-2023-24657 | Med | 0.43 | 6.1 | 0.04 | Mar 8, 2023 | phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. | ||
| CVE-2023-1211 | Hig | 0.43 | 7.2 | 0.03 | Mar 7, 2023 | SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2. | ||
| CVE-2026-75105 | Hig | 0.42 | 7.5 | 0.00 | Aug 17, 2026 | phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database… | ||
| CVE-2024-41355 | Med | 0.42 | 6.5 | 0.00 | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php. | ||
| CVE-2025-61078 | Med | 0.40 | 6.1 | 0.00 | Dec 9, 2025 | Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint. | ||
| CVE-2021-35438 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2021 | phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator. |
- risk 0.68cvss 9.8epss 0.10
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
- risk 0.67cvss 9.8epss 0.04
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.01
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.02
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old…
- risk 0.52cvss 9.1epss 0.01
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched…
- risk 0.52cvss 7.2epss 0.25
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
- risk 0.49cvss 8.6epss 0.00
phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
- risk 0.49cvss 7.1epss 0.01
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
- risk 0.46cvss 7.1epss 0.00
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
- risk 0.46cvss 7.1epss 0.00
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
- risk 0.43cvss 6.1epss 0.04
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
- risk 0.43cvss 7.2epss 0.03
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
- risk 0.42cvss 7.5epss 0.00
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database…
- risk 0.42cvss 6.5epss 0.00
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.
- risk 0.40cvss 6.1epss 0.01
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.