CVE-2025-2292: Xorcom Completepbx

Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.This issue affects CompletePBX: through 5.2.35.

Affected products

  • Xorcom Completepbx: before 5.2.36.1 (fixed in 5.2.36.1)

Published 2025-03-31. Last modified 2026-06-17.