VYPR

Vendor CVEs

Froxlor

All CVEs

77 total · sorted by risk
  • CVE-2023-0315HigJan 16, 2023
    risk 0.61cvss 8.8epss 0.98

    Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

  • CVE-2021-42325CriOct 12, 2021
    risk 0.61cvss 9.8epss 0.12

    Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

  • CVE-2026-100717CriSep 26, 2026
    risk 0.57cvss 9.9epss —

    froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This…

  • CVE-2026-100716CriSep 26, 2026
    risk 0.57cvss 9.9epss —

    Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that…

  • CVE-2026-90937CriSep 14, 2026
    risk 0.57cvss 9.9epss 0.00

    froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost…

  • CVE-2026-41228CriApr 23, 2026
    risk 0.57cvss 9.9epss 0.01

    Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set…

  • CVE-2023-6069CriNov 10, 2023
    risk 0.57cvss 9.9epss 0.01

    Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.

  • CVE-2023-3173CriJun 9, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.

  • CVE-2023-1307CriMar 10, 2023
    risk 0.57cvss 9.8epss 0.01

    Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

  • CVE-2015-5959CriSep 6, 2017
    risk 0.57cvss 9.8epss 0.03

    Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.

  • CVE-2016-5100CriFeb 13, 2017
    risk 0.57cvss 9.8epss 0.02

    Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.

  • CVE-2023-2034HigApr 14, 2023
    risk 0.56cvss 8.8epss 0.71

    Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

  • CVE-2026-100715CriSep 26, 2026
    risk 0.55cvss 9.6epss —

    Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink…

  • CVE-2024-34070CriMay 14, 2024
    risk 0.55cvss 9.6epss 0.01

    Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the…

  • CVE-2026-100714CriSep 26, 2026
    risk 0.52cvss 9.1epss —

    Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in…

  • CVE-2026-62988CriAug 18, 2026
    risk 0.52cvss 9.0epss 0.01

    Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and…

  • CVE-2026-41229CriApr 23, 2026
    risk 0.52cvss 9.1epss 0.01

    Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a…

  • CVE-2026-26279CriMar 3, 2026
    risk 0.52cvss 9.1epss 0.01

    Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary…

  • CVE-2023-0877HigFeb 17, 2023
    risk 0.51cvss 8.8epss 0.04

    Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.

  • CVE-2026-100720HigSep 26, 2026
    risk 0.50cvss 8.7epss —

    Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store…

  • CVE-2026-54347HigAug 18, 2026
    risk 0.50cvss 8.7epss 0.00

    Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content from Text::wordwrap without HTML…

  • CVE-2026-41236HigJun 4, 2026
    risk 0.50cvss 8.8epss 0.01

    Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` under a customer-controlled…

  • CVE-2026-30932HigMar 24, 2026
    risk 0.50cvss 8.8epss 0.01

    Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and…

  • CVE-2023-1033HigFeb 25, 2023
    risk 0.50cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.

  • CVE-2023-0671HigFeb 4, 2023
    risk 0.50cvss 8.8epss 0.01

    Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.

  • CVE-2020-10235HigMar 9, 2020
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in…

  • CVE-2026-41237HigJun 4, 2026
    risk 0.49cvss —epss 0.00

    Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input…

  • CVE-2026-41235HigJun 4, 2026
    risk 0.49cvss —epss 0.00

    Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when…

  • CVE-2026-41230HigApr 23, 2026
    risk 0.48cvss 8.5epss 0.01

    Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/elseif validation…

  • CVE-2026-52793HigAug 18, 2026
    risk 0.46cvss 8.1epss 0.00

    Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an administrator or customer account without checking type_2fa, validating a TOTP…

  • CVE-2026-100713HigSep 26, 2026
    risk 0.44cvss 7.8epss —

    Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile()…

  • CVE-2026-100711HigSep 26, 2026
    risk 0.42cvss 7.5epss —

    froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing…

  • CVE-2026-100709HigSep 26, 2026
    risk 0.42cvss 7.5epss —

    Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and…

  • CVE-2026-41234HigJun 4, 2026
    risk 0.42cvss 7.6epss 0.00

    Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which…

  • CVE-2026-41231HigApr 23, 2026
    risk 0.42cvss 7.5epss 0.01

    Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing the symlink validation that…

  • CVE-2020-36978MedJan 27, 2026
    risk 0.42cvss 6.4epss 0.00

    Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer…

  • CVE-2023-50256HigJan 3, 2024
    risk 0.42cvss 7.5epss 0.01

    Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory…

  • CVE-2023-2666HigMay 12, 2023
    risk 0.42cvss 7.5epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.

  • CVE-2018-12642HigJun 22, 2018
    risk 0.42cvss 7.5epss 0.01

    Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

  • CVE-2024-58383HigSep 14, 2026
    risk 0.40cvss 7.3epss 0.00

    Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are…

  • CVE-2026-54348HigAug 18, 2026
    risk 0.40cvss 7.2epss 0.01

    Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.ip without enforcing numeric element types.…

  • CVE-2023-3668HigJul 14, 2023
    risk 0.40cvss 7.2epss 0.01

    Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.

  • CVE-2023-3172HigJun 9, 2023
    risk 0.40cvss 7.2epss 0.01

    Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

  • CVE-2018-1000527HigJun 26, 2018
    risk 0.40cvss 7.2epss 0.03

    Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution. This attack appear to be exploitable via Passing malicious PHP objection in $_POST['ssl_ipandport']. This…

  • CVE-2026-100718HigSep 26, 2026
    risk 0.39cvss 7.1epss —

    Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1, mail.allow_external_domains…

  • CVE-2026-100708HigSep 26, 2026
    risk 0.39cvss 7.1epss —

    Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are…

  • CVE-2020-10237MedMar 9, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at…

  • CVE-2026-100719MedSep 26, 2026
    risk 0.35cvss 6.5epss —

    Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, enabling offline cracking…

  • CVE-2026-100712MedSep 26, 2026
    risk 0.35cvss 6.5epss —

    froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=delete), with no confirmation, re-authentication, or CSRF token. The global CSRF…

  • CVE-2026-90767MedSep 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent…

Page 1 of 2