vciy

CVEs we hold for Froxlor

Records whose assigning authority named Froxlor as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-90937froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLfroxlor
CVE-2026-90936Froxlor before 2.3.7 Information Disclosure via customer_email.phpfroxlor
CVE-2026-90935Froxlor before 2.3.7 Authorization Bypass via Mysqls.add APIfroxlor
CVE-2026-90767Froxlor before 2.3.12 SSH Key Injection via authorized_keysFroxlor
CVE-2026-62988Froxlor: Credential and 2FA secret disclosure via Froxlor API endpointsfroxlor
CVE-2026-55593Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery Protectionfroxlor
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsfroxlor
CVE-2026-54348Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltrationfroxlor
CVE-2026-54347Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeoverfroxlor
CVE-2026-52793Froxlor: API Authentication bypasses 2FA Authenticationfroxlor
CVE-2026-41237Froxlor has an incomplete fix for CVE-2026-30932froxlor
CVE-2026-41236Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` pathfroxlor
CVE-2026-41235Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcementfroxlor
CVE-2026-41234Froxlor: BIND Zone File Injection via TXT Record Contentfroxlor
CVE-2026-41233Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()froxlor
CVE-2026-41232Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email…froxlor
CVE-2026-41231Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cronfroxlor
CVE-2026-41230Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()froxlor
CVE-2026-41229Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)froxlor
CVE-2026-41228Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Executionfroxlor
CVE-2026-30932Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones APIfroxlor
CVE-2026-26279Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command InjectionFroxlor
CVE-2025-48958Froxlor has an HTML Injection VulnerabilityFroxlor
CVE-2025-29773Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account…Froxlor
CVE-2024-58383Froxlor before 2.2.0 Insecure File Permissions mysql.conffroxlor
CVE-2024-34070Froxlor Vulnerable to Blind XSS Leading to Froxlor Application CompromiseFroxlor
CVE-2023-6069Improper Link Resolution Before File Access in froxlor/froxlorfroxlor/froxlor
CVE-2023-5564Cross-site Scripting (XSS) - Stored in froxlor/froxlorfroxlor/froxlor
CVE-2023-50256Froxlor username/surname AND company field BypassFroxlor
CVE-2023-4829Cross-site Scripting (XSS) - Stored in froxlor/froxlorfroxlor/froxlor
CVE-2023-4304Business Logic Errors in froxlor/froxlorfroxlor/froxlor
CVE-2023-3668Improper Encoding or Escaping of Output in froxlor/froxlorfroxlor/froxlor
CVE-2023-3192Session Fixation in froxlor/froxlorfroxlor/froxlor
CVE-2023-3173Improper Restriction of Excessive Authentication Attempts in froxlor/froxlorfroxlor/froxlor
CVE-2023-3172Path Traversal in froxlor/froxlorfroxlor/froxlor
CVE-2023-2666Allocation of Resources Without Limits or Throttling in froxlor/froxlorfroxlor/froxlor
CVE-2023-2034Unrestricted Upload of File with Dangerous Type in froxlor/froxlorfroxlor/froxlor
CVE-2023-1307Authentication Bypass by Primary Weakness in froxlor/froxlorfroxlor/froxlor
CVE-2023-1033Cross-Site Request Forgery (CSRF) in froxlor/froxlorfroxlor/froxlor
CVE-2023-0877Code Injection in froxlor/froxlorfroxlor/froxlor
CVE-2023-0671Code Injection in froxlor/froxlorfroxlor/froxlor
CVE-2023-0572Unchecked Error Condition in froxlor/froxlorfroxlor/froxlor
CVE-2023-0566Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlorfroxlor/froxlor
CVE-2023-0565Business Logic Errors in froxlor/froxlorfroxlor/froxlor
CVE-2023-0564Weak Password Requirements in froxlor/froxlorfroxlor/froxlor
CVE-2023-0316Path Traversal: '\..\filename' in froxlor/froxlorfroxlor/froxlor
CVE-2023-0315Command Injection in froxlor/froxlorfroxlor/froxlor
CVE-2022-4868Improper Authorization in froxlor/froxlorfroxlor/froxlor
CVE-2022-4867Cross-Site Request Forgery (CSRF) in froxlor/froxlorfroxlor/froxlor
CVE-2022-4864Argument Injection in froxlor/froxlorfroxlor/froxlor
CVE-2022-3869Code Injection in froxlor/froxlorfroxlor/froxlor
CVE-2022-3721Code Injection in froxlor/froxlorfroxlor/froxlor
CVE-2022-3017Cross-Site Request Forgery (CSRF) in froxlor/froxlorfroxlor/froxlor
CVE-2020-36978Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site ScriptingFroxlor Server Management Panel

54 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.