CVE-2019-19851: Sangoma FreePBX

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.

Affected products

  • Sangoma FreePBX: up to and including 13.0.4.7; from 14.0.0.0, up to and including 14.0.24; from 15.0.0.0, up to and including 15.0.2.20

Published 2020-03-16. Last modified 2026-06-17.