Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpipam MEDIUM 6.1
CVE-2025-61078

Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the …

Mitigation only
Fix from $1,600 2025-12-09
Phpipam MEDIUM 6.1
CVE-2024-10727

A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the applic…

Fix: after 1.6
Fix from $1,600 2025-03-20
Phpipam MEDIUM 5.4
CVE-2024-10721

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject ma…

Patch available
Fix from $1,600 2025-03-20
Phpipam MEDIUM 5.4
CVE-2024-10722

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scr…

Fix: 1.7.0+
Fix from $1,600 2025-03-20
Phpipam MEDIUM 5.4
CVE-2024-10723

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject ma…

Fix: 1.7.0+
Fix from $1,600 2025-03-20
Phpipam MEDIUM 5.4
CVE-2024-10724

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when e…

Fix: 1.7.0+
Fix from $1,600 2025-03-20
Phpipam MEDIUM 5.4
CVE-2024-10725

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious …

Fix: 1.7.0+
Fix from $1,600 2025-03-20
Phpipam HIGH 7.5
CVE-2024-10718

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send th…

Fix: 1.7.0+
Fix from $1,950 2025-03-20
Phpipam MEDIUM 6.1
CVE-2024-10720

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device Management' sectio…

Fix: 1.7.0+
Fix from $1,600 2025-03-20
Phpipam MEDIUM 5.4
CVE-2024-10719

A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerabi…

Fix: 1.7.0+
Fix from $1,600 2025-03-20
Phpipam MEDIUM 5.9
CVE-2024-0787

phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X…

Fix: 1.7.0+
Fix from $1,600 2024-11-15
Phpipam MEDIUM 6.1
CVE-2024-41358

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

Patch available
Fix from $1,600 2024-08-29
Phpipam HIGH 7.1
CVE-2024-41353

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php

No fix yet
Fix from $1,950 2024-07-26
Phpipam HIGH 7.1
CVE-2024-41354

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php

No fix yet
Fix from $1,950 2024-07-26
Phpipam HIGH 7.1
CVE-2024-41357

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

No fix yet
Fix from $1,950 2024-07-26
Phpipam MEDIUM 6.5
CVE-2024-41355

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

No fix yet
Fix from $1,600 2024-07-26
Phpipam HIGH 7.5
CVE-2023-41580

Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerabi…

Fix: 1.5.2+
Fix from $1,950 2023-10-02
Phpipam MEDIUM 6.1
CVE-2023-24657

phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.

Patch available
Fix from $1,600 2023-03-08
Phpipam HIGH 7.2
CVE-2023-1211

SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.

Fix: 1.5.2+
Fix from $1,950 2023-03-07
Phpipam MEDIUM 6.1
CVE-2023-0676

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.

Fix: 1.5.1+
Fix from $1,600 2023-02-04
Phpipam MEDIUM 6.1
CVE-2023-0677

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.

Fix: 1.5.1+
Fix from $1,600 2023-02-04
Phpipam MEDIUM 5.3
CVE-2023-0678EPSS 37%

Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

Fix: 1.5.1+
Fix from $1,600 2023-02-04
Phpipam MEDIUM 6.1
CVE-2022-3845

A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/a…

Fix: 1.5.0+
Fix from $1,600 2022-11-02
Phpipam CRITICAL 9.8
CVE-2022-41443

phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

No fix yet
Fix from $2,300 2022-10-03
Phpipam MEDIUM 6.5
CVE-2022-1223

Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Fix: 1.4.6+
Fix from $1,600 2022-04-04
Phpipam MEDIUM 6.5
CVE-2022-1224

Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Fix: 1.4.6+
Fix from $1,600 2022-04-04
Phpipam MEDIUM 6.5
CVE-2022-1225

Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

Fix: 1.4.6+
Fix from $1,600 2022-04-04
Phpipam MEDIUM 6.1
CVE-2021-46426

phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

Patch available
Fix from $1,600 2022-03-25
Phpipam HIGH 7.2
CVE-2022-23046EPSS 25%

PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/ed…

No fix yet
Fix from $1,950 2022-01-19
Phpipam MEDIUM 6.1
CVE-2021-35438

phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.

Patch available
Fix from $1,600 2021-06-23