CVE-2019-16693: Phpipam

Critical severity, CVSS 9.8. EPSS: 4.3% chance of exploitation in the next 30 days.

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

Affected products

  • Phpipam Phpipam: up to and including 1.4

Published 2019-09-22. Last modified 2026-06-17.