VYPR

Froxlor

by Froxlor

Source repositories

CVEs (63)

  • CVE-2023-0566MedJan 29, 2023
    risk 0.33cvss 6.2epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.

  • CVE-2022-3869MedNov 5, 2022
    risk 0.33cvss 6.1epss 0.01

    Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

  • CVE-2020-29653MedApr 13, 2022
    risk 0.33cvss 6.1epss 0.01

    Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.

  • CVE-2020-10236MedMar 9, 2020
    risk 0.33cvss 6.1epss 0.00

    An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of…

  • CVE-2025-29773MedMar 13, 2025
    risk 0.31cvss 5.8epss 0.00

    Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential issues with account identification and…

  • CVE-2025-48958MedJun 2, 2025
    risk 0.29cvss 5.5epss 0.00

    Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, credential theft, and…

  • CVE-2023-0565MedJan 29, 2023
    risk 0.29cvss 5.5epss 0.01

    Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.

  • CVE-2023-0316MedJan 16, 2023
    risk 0.29cvss 5.5epss 0.01

    Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.

  • CVE-2026-54543MedAug 18, 2026
    risk 0.28cvss 5.4epss 0.00

    Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab characters, semicolons, or unsupported DNS…

  • CVE-2026-41233MedApr 23, 2026
    risk 0.28cvss 5.4epss 0.00

    Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller…

  • CVE-2023-4829MedOct 13, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.

  • CVE-2023-3192MedJun 11, 2023
    risk 0.28cvss 5.4epss 0.00

    Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.

  • CVE-2023-0572MedJan 29, 2023
    risk 0.28cvss 5.3epss 0.01

    Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.

  • CVE-2023-0564MedJan 29, 2023
    risk 0.28cvss 5.4epss 0.00

    Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.

  • CVE-2022-4864MedDec 30, 2022
    risk 0.28cvss 5.4epss 0.00

    Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

  • CVE-2026-41232MedApr 23, 2026
    risk 0.26cvss 5.0epss 0.00

    Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to…

  • CVE-2023-5564MedOct 13, 2023
    risk 0.24cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.

  • CVE-2022-3721MedNov 4, 2022
    risk 0.23cvss 4.6epss 0.01

    Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

  • CVE-2026-90936MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete…

  • CVE-2026-90935MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer…