Vulnerabilities > Fusionpbx > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-08-18 CVE-2022-35153 Improper Encoding or Escaping of Output vulnerability in Fusionpbx 5.0.1
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
network
low complexity
fusionpbx CWE-116
critical
9.8
2022-05-04 CVE-2022-28055 OS Command Injection vulnerability in Fusionpbx
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
network
low complexity
fusionpbx CWE-78
critical
9.8