CVE-2026-97818 is a HIGH severity vulnerability in phpIPAM through version 1.8.3, involving incorrect authorization in the User.php controller. This issue allows for unauthorized access, with a CVSS score of 8.6. The CVE was published on 2026-09-25T05:17:08.120Z and has not been modified since then. The vulnerability affects phpIPAM installations, and defenders should verify and patch their systems to pre [truncated]
CVE-2026-67602 is a critical authentication bypass vulnerability in phpIPAM's REST API, allowing unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. This vulnerability, with a CVSS score of 9.3, enables attackers to read, write, and delete all IP address management records. The vulnerability affects phpIPAM versions prior to 1.8.2 and requires immedia [truncated]
phpIPAM through 1.8.1 has an information disclosure vulnerability in temporary subnet share functionality. An unauthenticated party with a valid temporary share URL can enumerate subnet IDs to read IP address records across all sections and subnets, including sensitive information like hostnames, DNS names, MAC addresses, and notes. This vulnerability allows unauthorized access to sensitive information, p [truncated]
CVE-2026-12194 is an authenticated local file inclusion vulnerability in PHPIPAM that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations. This vulnerability has a CVSS score of 2.3 and a severity of LOW. The CVE was published on 2026-07-04T08:16:20.643Z and has not been modified since then. The vuln [truncated]
CVE-2017-6481 is a medium-severity cross-site scripting issue affecting phpipam 1.2. According to the NVD record, multiple pages accepted user-supplied data with insufficient filtration, including the instructions parameter in app/admin/instructions/preview.php and subnetId in app/admin/powerDNS/refresh-ptr-records.php. An attacker could cause a victim’s browser to execute arbitrary HTML and script in the [truncated]