CVEs we hold for Froxlor
Records whose assigning authority named Froxlor as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-90937froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLfroxlor
CVE-2026-55593Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery Protectionfroxlor
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsfroxlor
CVE-2026-54348Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltrationfroxlor
CVE-2026-54347Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeoverfroxlor
CVE-2026-41236Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` pathfroxlor
CVE-2026-41235Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcementfroxlor
CVE-2026-41233Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()froxlor
CVE-2026-41232Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email…froxlor
CVE-2026-41231Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cronfroxlor
CVE-2026-41230Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()froxlor
CVE-2026-41229Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)froxlor
CVE-2026-41228Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Executionfroxlor
CVE-2026-30932Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones APIfroxlor
CVE-2026-26279Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command InjectionFroxlor
CVE-2025-29773Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account…Froxlor
CVE-2023-3173Improper Restriction of Excessive Authentication Attempts in froxlor/froxlorfroxlor/froxlor
CVE-2023-0566Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlorfroxlor/froxlor
CVE-2020-36978Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site ScriptingFroxlor Server Management Panel
54 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.