VYPR

Vendor CVEs

Froxlor

All CVEs

64 total · sorted by risk
  • CVE-2026-41233MedApr 23, 2026
    risk 0.28cvss 5.4epss 0.00

    Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller…

  • CVE-2023-4829MedOct 13, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.

  • CVE-2023-3192MedJun 11, 2023
    risk 0.28cvss 5.4epss 0.00

    Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.

  • CVE-2023-0572MedJan 29, 2023
    risk 0.28cvss 5.3epss 0.01

    Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.

  • CVE-2023-0564MedJan 29, 2023
    risk 0.28cvss 5.4epss 0.00

    Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.

  • CVE-2022-4864MedDec 30, 2022
    risk 0.28cvss 5.4epss 0.00

    Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

  • CVE-2026-41232MedApr 23, 2026
    risk 0.26cvss 5.0epss 0.00

    Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to…

  • CVE-2023-5564MedOct 13, 2023
    risk 0.24cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.

  • CVE-2022-3721MedNov 4, 2022
    risk 0.23cvss 4.6epss 0.01

    Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

  • CVE-2026-90936MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying arbitrary senderid parameters in delete…

  • CVE-2026-90935MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer…

  • CVE-2022-4868MedDec 31, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

  • CVE-2022-4867MedDec 31, 2022
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

  • CVE-2023-4304LowAug 11, 2023
    risk 0.18cvss 3.8epss 0.01

    Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

Page 2 of 2