CVE-2024-10724: Phpipam

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.

Affected products

  • Phpipam Phpipam: before 1.7.0 (fixed in 1.7.0)

Published 2025-03-20. Last modified 2026-06-17.