📦 Phpipam

by Phpipam

🔍 What is Phpipam?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-41353

HIGH CVSS 7.1 Jul 26, 2024

CVE-2024-41353 is a cross-site scripting (XSS) vulnerability in phpipam 1.6 that allows attackers to inject malicious scripts into the group editing interface. This affects administrators who use the ...

CVE-2024-41357

HIGH CVSS 7.1 Jul 26, 2024

CVE-2024-41357 is a cross-site scripting (XSS) vulnerability in phpipam 1.6 that allows attackers to inject malicious scripts via the /app/admin/powerDNS/record-edit.php endpoint. This affects adminis...

CVE-2023-1211

HIGH CVSS 7.2 Mar 7, 2023

This SQL injection vulnerability in phpIPAM allows attackers to execute arbitrary SQL commands through unsanitized user input. It affects all phpIPAM installations prior to version 1.5.2. Attackers co...

CVE-2022-23046

HIGH CVSS 7.2 Jan 19, 2022

This SQL injection vulnerability in phpIPAM v1.4.4 allows authenticated admin users to execute arbitrary SQL commands via the 'subnet' parameter in the BGP mapping search functionality. Attackers with...

CVE-2024-55093

MEDIUM CVSS 5.4 Mar 31, 2025

phpIPAM through version 1.7.3 contains a reflected Cross-Site Scripting (XSS) vulnerability in its installation scripts. This allows attackers to inject malicious scripts into web pages viewed by user...

CVE-2024-10721

MEDIUM CVSS 5.4 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in phpipam/phpipam version 1.5.2 allows attackers to inject malicious scripts into the circuits options page. When other users view the affected page,...

CVE-2024-10723

MEDIUM CVSS 5.4 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in phpipam/phpipam version 1.5.2 allows attackers to inject malicious scripts into the NAT tool's destination address field. When users interact with ...

CVE-2024-10725

MEDIUM CVSS 5.4 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in phpipam version 1.5.2 allows attackers to inject malicious scripts into NAT destination address fields. These scripts execute when other users view...

CVE-2024-10719

MEDIUM CVSS 5.4 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in phpipam version 1.5.2 allows attackers to inject malicious scripts via the 'option' parameter in circuits functionality. When executed in a user's ...

CVE-2024-41356

MEDIUM CVSS 4.7 Jul 26, 2024

phpipam 1.6 contains a cross-site scripting vulnerability in the firewall zone network editing interface. This allows attackers to inject malicious scripts that execute in victims' browsers when they ...

CVE-2023-0676

MEDIUM CVSS 6.1 Feb 4, 2023

This CVE describes a reflected cross-site scripting (XSS) vulnerability in phpIPAM versions prior to 1.5.1. Attackers can inject malicious scripts into web pages that are then executed in victims' bro...

CVE-2025-60912

LOW CVSS 3.3 Dec 8, 2025

phpIPAM v1.7.3 contains a CSRF vulnerability in the database export functionality that allows attackers to trigger unauthorized database dump downloads. Attackers can craft malicious HTTP GET requests...