Freepbx · Freepbx · CVE-2026-28284
**Name of the Vulnerable Software and Affected Versions**
FreePBX versions prior to 16.0.10
FreePBX versions prior to 17.0.5
**Description**
FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. These issues allow an attacker with valid credentials to potentially manipulate database queries.
**Recommendations**
Update to FreePBX version 16.0.10 or later.
Update to FreePBX version 17.0.5 or later.