Froxlor
by Froxlor
Source repositories
CVEs (63)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0566 | Med | 0.33 | 6.2 | 0.00 | Jan 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10. | ||
| CVE-2022-3869 | Med | 0.33 | 6.1 | 0.01 | Nov 5, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2. | ||
| CVE-2020-29653 | Med | 0.33 | 6.1 | 0.01 | Apr 13, 2022 | Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags. | ||
| CVE-2020-10236 | Med | 0.33 | 6.1 | 0.00 | Mar 9, 2020 | An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of… | ||
| CVE-2025-29773 | Med | 0.31 | 5.8 | 0.00 | Mar 13, 2025 | Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential issues with account identification and… | ||
| CVE-2025-48958 | Med | 0.29 | 5.5 | 0.00 | Jun 2, 2025 | Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, credential theft, and… | ||
| CVE-2023-0565 | Med | 0.29 | 5.5 | 0.01 | Jan 29, 2023 | Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10. | ||
| CVE-2023-0316 | Med | 0.29 | 5.5 | 0.01 | Jan 16, 2023 | Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0. | ||
| CVE-2026-54543 | Med | 0.28 | 5.4 | 0.00 | Aug 18, 2026 | Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab characters, semicolons, or unsupported DNS… | ||
| CVE-2026-41233 | Med | 0.28 | 5.4 | 0.00 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller… | ||
| CVE-2023-4829 | Med | 0.28 | 5.4 | 0.00 | Oct 13, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22. | ||
| CVE-2023-3192 | Med | 0.28 | 5.4 | 0.00 | Jun 11, 2023 | Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0. | ||
| CVE-2023-0572 | Med | 0.28 | 5.3 | 0.01 | Jan 29, 2023 | Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10. | ||
| CVE-2023-0564 | Med | 0.28 | 5.4 | 0.00 | Jan 29, 2023 | Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10. | ||
| CVE-2022-4864 | Med | 0.28 | 5.4 | 0.00 | Dec 30, 2022 | Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||
| CVE-2026-41232 | Med | 0.26 | 5.0 | 0.00 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to… | ||
| CVE-2023-5564 | Med | 0.24 | 4.8 | 0.00 | Oct 13, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1. | ||
| CVE-2022-3721 | Med | 0.23 | 4.6 | 0.01 | Nov 4, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39. | ||
| CVE-2026-90936 | Med | 0.21 | 4.3 | 0.00 | Sep 14, 2026 | Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete… | ||
| CVE-2026-90935 | Med | 0.21 | 4.3 | 0.00 | Sep 14, 2026 | Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer… |
- risk 0.33cvss 6.2epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.
- risk 0.33cvss 6.1epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
- risk 0.33cvss 6.1epss 0.01
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.
- risk 0.33cvss 6.1epss 0.00
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of…
- risk 0.31cvss 5.8epss 0.00
Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential issues with account identification and…
- risk 0.29cvss 5.5epss 0.00
Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, credential theft, and…
- risk 0.29cvss 5.5epss 0.01
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.
- risk 0.29cvss 5.5epss 0.01
Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.
- risk 0.28cvss 5.4epss 0.00
Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab characters, semicolons, or unsupported DNS…
- risk 0.28cvss 5.4epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller…
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.
- risk 0.28cvss 5.4epss 0.00
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
- risk 0.28cvss 5.3epss 0.01
Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
- risk 0.28cvss 5.4epss 0.00
Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
- risk 0.28cvss 5.4epss 0.00
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
- risk 0.26cvss 5.0epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to…
- risk 0.24cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.
- risk 0.23cvss 4.6epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
- risk 0.21cvss 4.3epss 0.00
Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete…
- risk 0.21cvss 4.3epss 0.00
Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer…
Page 3 of 4