VulnSea

Froxlor vulnerabilities

CVEs whose affected-version data names the Froxlor package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2024-58383High· 7.3PoC
1w ago

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. O…

Midnightfroxlor · froxlorEPSS 0.10%via NVD
CVE-2026-90937Critical· 9.9
1w ago

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal new…

Midnightfroxlor · froxlorEPSS 0.26%via NVD
CVE-2026-90936Medium· 4.3PoC
1w ago

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying a…

Twilightfroxlor · froxlorEPSS 0.23%via NVD
CVE-2026-90935Medium· 4.3PoC
1w ago

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on for…

Twilightfroxlor · froxlorEPSS 0.21%via NVD
CVE-2026-90767Medium· 6.5PoC
1w ago

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with opti…

Twilightfroxlor · FroxlorEPSS 0.25%via NVD
Froxlor vulnerabilities (CVEs) · VulnSea