Froxlor
Products
2- 76 CVEs
- 1 CVE
Recent CVEs
77| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0315 | Hig | 0.61 | 8.8 | 0.98 | Jan 16, 2023 | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | ||
| CVE-2021-42325 | Cri | 0.61 | 9.8 | 0.12 | Oct 12, 2021 | Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name. | ||
| CVE-2026-100717 | Cri | 0.57 | 9.9 | 0.00 | Sep 26, 2026 | froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This… | ||
| CVE-2026-100716 | Cri | 0.57 | 9.9 | 0.00 | Sep 26, 2026 | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that… | ||
| CVE-2026-90937 | Cri | 0.57 | 9.9 | 0.00 | Sep 14, 2026 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost… | ||
| CVE-2026-41228 | Cri | 0.57 | 9.9 | 0.01 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set… | ||
| CVE-2023-6069 | Cri | 0.57 | 9.9 | 0.01 | Nov 10, 2023 | Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0. | ||
| CVE-2023-3173 | Cri | 0.57 | 9.8 | 0.01 | Jun 9, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20. | ||
| CVE-2023-1307 | Cri | 0.57 | 9.8 | 0.01 | Mar 10, 2023 | Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. | ||
| CVE-2015-5959 | Cri | 0.57 | 9.8 | 0.03 | Sep 6, 2017 | Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log. | ||
| CVE-2016-5100 | Cri | 0.57 | 9.8 | 0.02 | Feb 13, 2017 | Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value. | ||
| CVE-2023-2034 | Hig | 0.56 | 8.8 | 0.71 | Apr 14, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14. | ||
| CVE-2026-100715 | Cri | 0.55 | 9.6 | 0.00 | Sep 26, 2026 | Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink… | ||
| CVE-2024-34070 | Cri | 0.55 | 9.6 | 0.01 | May 14, 2024 | Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the… | ||
| CVE-2026-100714 | Cri | 0.52 | 9.1 | 0.01 | Sep 26, 2026 | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in… | ||
| CVE-2026-62988 | Cri | 0.52 | 9.0 | 0.01 | Aug 18, 2026 | Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and… | ||
| CVE-2026-41229 | Cri | 0.52 | 9.1 | 0.01 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a… | ||
| CVE-2026-26279 | Cri | 0.52 | 9.1 | 0.01 | Mar 3, 2026 | Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary… | ||
| CVE-2023-0877 | Hig | 0.51 | 8.8 | 0.04 | Feb 17, 2023 | Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11. | ||
| CVE-2026-100720 | Hig | 0.50 | 8.7 | 0.00 | Sep 26, 2026 | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store… |
- risk 0.61cvss 8.8epss 0.98
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
- risk 0.61cvss 9.8epss 0.12
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
- risk 0.57cvss 9.9epss 0.00
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This…
- risk 0.57cvss 9.9epss 0.00
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that…
- risk 0.57cvss 9.9epss 0.00
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost…
- risk 0.57cvss 9.9epss 0.01
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set…
- risk 0.57cvss 9.9epss 0.01
Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.
- risk 0.57cvss 9.8epss 0.01
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
- risk 0.57cvss 9.8epss 0.01
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
- risk 0.57cvss 9.8epss 0.03
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.
- risk 0.57cvss 9.8epss 0.02
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
- risk 0.56cvss 8.8epss 0.71
Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
- risk 0.55cvss 9.6epss 0.00
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink…
- risk 0.55cvss 9.6epss 0.01
Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the…
- risk 0.52cvss 9.1epss 0.01
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in…
- risk 0.52cvss 9.0epss 0.01
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and…
- risk 0.52cvss 9.1epss 0.01
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a…
- risk 0.52cvss 9.1epss 0.01
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary…
- risk 0.51cvss 8.8epss 0.04
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
- risk 0.50cvss 8.7epss 0.00
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store…