These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to [truncated]
CVE-2026-9587 is a HIGH severity vulnerability in Sangoma Switchvox SMB Edition 8.3. The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope. This vulnerability has a CVSS scor [truncated]
A critical SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3. The /pa endpoint processes XML content and directly concatenates user-controlled input into PostgreSQL queries without sanitization, allowing unauthenticated remote attackers to execute arbitrary SQL statements. This vulnerability has a CVSS score of 9.3 and is considered CRITICAL. Organizations using Sangoma Switchvox SMB [truncated]
CVE-2026-9585 is a HIGH severity vulnerability in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers, allowing unauthenticated reflected cross-site scripting. This vulnerability allows attacker-controlled script execution within a victim's browser. Administrators and users of [truncated]
CVE-2025-64328 is a Sangoma FreePBX operating-system command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-02-03. That listing means the issue is considered actively exploited in the wild, so defensive action should be prioritized immediately. The supplied corpus does not include affected versions, CVSS scoring, or vendor advisory text, so remediation shoul [truncated]
CVE-2019-19006 is a Sangoma FreePBX improper authentication vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-03. The available source corpus does not provide detailed exploit mechanics, but it does confirm this issue is considered known exploited and that remediation should follow vendor guidance. CISA’s KEV entry also points to a Sangoma/FreePBX vendor note ti [truncated]
CVE-2025-57819 is a Sangoma FreePBX authentication bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-08-29. Because it is in KEV, defenders should treat it as an active-exploitation risk and move quickly to vendor-directed mitigation, patching, or removal if mitigation is not possible.