Vulnerabilities > 3CX > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-25 CVE-2023-49954 SQL Injection vulnerability in 3CX
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.
network
low complexity
3cx CWE-89
critical
9.8
2022-05-06 CVE-2022-28005 Insufficiently Protected Credentials vulnerability in 3CX
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
network
low complexity
3cx CWE-522
critical
9.8
2022-03-28 CVE-2021-45490 Improper Certificate Validation vulnerability in 3CX
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.
network
low complexity
3cx CWE-295
critical
9.1
2020-03-20 CVE-2019-12498 Missing Authorization vulnerability in 3CX Live Chat
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
network
low complexity
3cx CWE-862
critical
9.8
2019-06-03 CVE-2019-11185 Unrestricted Upload of File with Dangerous Type vulnerability in 3CX Live Chat
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.
network
low complexity
3cx CWE-434
critical
9.8
2018-07-02 CVE-2018-12426 Unrestricted Upload of File with Dangerous Type vulnerability in 3CX Live Chat
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.
network
low complexity
3cx CWE-434
critical
9.8