Home/Product/phpipam
Product

phpipam

52 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-61078
all versions
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web scri
6.1MEDIUM
CVE-2025-60912
<= 1.7.3
phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql
3.3LOW
CVE-2024-55093
<= 1.7.3
phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.
5.4MEDIUM
CVE-2024-10727
>= 1.5.0 and <= 1.6
A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability ari
6.1MEDIUM
CVE-2024-10725
< 1.7.0
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker t
5.4MEDIUM
CVE-2024-10724
< 1.7.0
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translat
5.4MEDIUM
CVE-2024-10723
< 1.7.0
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an at
5.4MEDIUM
CVE-2024-10722
< 1.7.0
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to i
5.4MEDIUM
CVE-2024-10721
all versions
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an at
5.4MEDIUM
CVE-2024-10720
< 1.7.0
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device
6.1MEDIUM
CVE-2024-10719
< 1.7.0
A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functional
5.4MEDIUM
CVE-2024-10718
< 1.7.0
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the us
7.5HIGH
CVE-2024-0787
< 1.7.0
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for us
5.9MEDIUM
CVE-2022-1226
< 1.4.7
A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaSc
4.8MEDIUM
CVE-2024-41358
all versions
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
6.1MEDIUM
CVE-2024-41354
all versions
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
7.1HIGH
CVE-2024-41353
all versions
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
7.1HIGH
CVE-2024-41357
all versions
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
7.1HIGH
CVE-2024-41356
all versions
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
4.7MEDIUM
CVE-2024-41355
all versions
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
6.5MEDIUM
CVE-2023-41580
< 1.5.2
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.
7.5HIGH
CVE-2023-4965
all versions
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality
2.7LOW
CVE-2023-24657
all versions
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subne
6.1MEDIUM
CVE-2023-1212
< 1.5.2
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
4.8MEDIUM
CVE-2023-1211
< 1.5.2
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
7.2HIGH
CVE-2023-0678
< 1.5.1
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
5.3MEDIUM
CVE-2023-0677
< 1.5.1
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
6.1MEDIUM
CVE-2023-0676
< 1.5.1
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
6.1MEDIUM
CVE-2022-3845
< 1.5.0
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionalit
2.4LOW
CVE-2022-41443
all versions
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
9.8CRITICAL
CVE-2022-1225
< 1.4.6
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
6.5MEDIUM
CVE-2022-1224
< 1.4.6
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
6.5MEDIUM
CVE-2022-1223
< 1.4.6
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
6.5MEDIUM
CVE-2021-46426
all versions
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
6.1MEDIUM
CVE-2022-23046
all versions
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via a
7.2HIGH
CVE-2022-23045
all versions
PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while upd
4.8MEDIUM
CVE-2021-35438
all versions
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP ca
6.1MEDIUM
CVE-2020-13225
all versions
phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instruc
4.8MEDIUM
CVE-2020-7988
all versions
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin,
8.8HIGH
CVE-2019-16696
<= 1.4
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
9.8CRITICAL
CVE-2019-16695
<= 1.4
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
9.8CRITICAL
CVE-2019-16694
<= 1.4
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
9.8CRITICAL
CVE-2019-16693
<= 1.4
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
9.8CRITICAL
CVE-2019-16692
<= 1.4
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
9.8CRITICAL
CVE-2019-1000010
<= 1.3.2
phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in
6.1MEDIUM
CVE-2018-1000870
<= 1.3.2
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute co
5.4MEDIUM
CVE-2018-1000869
all versions
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. Thi
9.8CRITICAL
CVE-2018-1000860
<= 1.3.2
phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie i
4.7MEDIUM
CVE-2018-10329
all versions
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.
6.1MEDIUM
CVE-2017-15640
< 1.3.1
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.
5.4MEDIUM
CVE-2017-6481
<= 1.2
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtratio
6.1MEDIUM
CVE-2015-6529
all versions
Multiple cross-site scripting (XSS) vulnerabilities in phpipam 1.1.010 allow remote attackers to inject arbitrary web script or HT
threatengine.sh