CVE-2026-12194 is an authenticated local file inclusion vulnerability in PHPIPAM that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations. This vulnerability has a CVSS score of 2.3 and a severity of LOW. The CVE was published on 2026-07-04T08:16:20.643Z and has not been modified since then. The vuln [truncated]
CVE-2017-6481 is a medium-severity cross-site scripting issue affecting phpipam 1.2. According to the NVD record, multiple pages accepted user-supplied data with insufficient filtration, including the instructions parameter in app/admin/instructions/preview.php and subnetId in app/admin/powerDNS/refresh-ptr-records.php. An attacker could cause a victim’s browser to execute arbitrary HTML and script in the [truncated]