PatchSiren

phpipam CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH phpipam CVE published 2026-09-25

CVE-2026-97818

CVE-2026-97818 is a HIGH severity vulnerability in phpIPAM through version 1.8.3, involving incorrect authorization in the User.php controller. This issue allows for unauthorized access, with a CVSS score of 8.6. The CVE was published on 2026-09-25T05:17:08.120Z and has not been modified since then. The vulnerability affects phpIPAM installations, and defenders should verify and patch their systems to pre [truncated]

CRITICAL phpipam CVE published 2026-08-24

CVE-2026-67602

CVE-2026-67602 is a critical authentication bypass vulnerability in phpIPAM's REST API, allowing unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. This vulnerability, with a CVSS score of 9.3, enables attackers to read, write, and delete all IP address management records. The vulnerability affects phpIPAM versions prior to 1.8.2 and requires immedia [truncated]

HIGH phpipam CVE published 2026-08-17

CVE-2026-75105

phpIPAM through 1.8.1 has an information disclosure vulnerability in temporary subnet share functionality. An unauthenticated party with a valid temporary share URL can enumerate subnet IDs to read IP address records across all sections and subnets, including sensitive information like hostnames, DNS names, MAC addresses, and notes. This vulnerability allows unauthorized access to sensitive information, p [truncated]

LOW phpipam CVE published 2026-07-04

CVE-2026-12194

CVE-2026-12194 is an authenticated local file inclusion vulnerability in PHPIPAM that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations. This vulnerability has a CVSS score of 2.3 and a severity of LOW. The CVE was published on 2026-07-04T08:16:20.643Z and has not been modified since then. The vuln [truncated]

MEDIUM Phpipam CVE published 2017-03-05

CVE-2017-6481

CVE-2017-6481 is a medium-severity cross-site scripting issue affecting phpipam 1.2. According to the NVD record, multiple pages accepted user-supplied data with insufficient filtration, including the instructions parameter in app/admin/instructions/preview.php and subnetId in app/admin/powerDNS/refresh-ptr-records.php. An attacker could cause a victim’s browser to execute arbitrary HTML and script in the [truncated]