CVE-2019-16991: Fusionpbx

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS.

Affected products

  • Fusionpbx Fusionpbx: up to and including 4.5.7

Published 2019-10-21. Last modified 2026-06-17.