Vendor CVEs
Froxlor
All CVEs
64 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41233 | Med | 0.28 | 5.4 | 0.00 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller… | ||
| CVE-2023-4829 | Med | 0.28 | 5.4 | 0.00 | Oct 13, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22. | ||
| CVE-2023-3192 | Med | 0.28 | 5.4 | 0.00 | Jun 11, 2023 | Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0. | ||
| CVE-2023-0572 | Med | 0.28 | 5.3 | 0.01 | Jan 29, 2023 | Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10. | ||
| CVE-2023-0564 | Med | 0.28 | 5.4 | 0.00 | Jan 29, 2023 | Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10. | ||
| CVE-2022-4864 | Med | 0.28 | 5.4 | 0.00 | Dec 30, 2022 | Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||
| CVE-2026-41232 | Med | 0.26 | 5.0 | 0.00 | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to… | ||
| CVE-2023-5564 | Med | 0.24 | 4.8 | 0.00 | Oct 13, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1. | ||
| CVE-2022-3721 | Med | 0.23 | 4.6 | 0.01 | Nov 4, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39. | ||
| CVE-2026-90936 | Med | 0.21 | 4.3 | 0.00 | Sep 14, 2026 | Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete… | ||
| CVE-2026-90935 | Med | 0.21 | 4.3 | 0.00 | Sep 14, 2026 | Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer… | ||
| CVE-2022-4868 | Med | 0.21 | 4.3 | 0.01 | Dec 31, 2022 | Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||
| CVE-2022-4867 | Med | 0.21 | 4.3 | 0.00 | Dec 31, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||
| CVE-2023-4304 | Low | 0.18 | 3.8 | 0.01 | Aug 11, 2023 | Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0. |
- risk 0.28cvss 5.4epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller…
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.
- risk 0.28cvss 5.4epss 0.00
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
- risk 0.28cvss 5.3epss 0.01
Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.
- risk 0.28cvss 5.4epss 0.00
Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
- risk 0.28cvss 5.4epss 0.00
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
- risk 0.26cvss 5.0epss 0.00
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to…
- risk 0.24cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.
- risk 0.23cvss 4.6epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
- risk 0.21cvss 4.3epss 0.00
Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete…
- risk 0.21cvss 4.3epss 0.00
Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer…
- risk 0.21cvss 4.3epss 0.01
Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
- risk 0.21cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
- risk 0.18cvss 3.8epss 0.01
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
Page 2 of 2