froxlor has 12 CVEs on record. Disclosure cadence is accelerating: 12 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 6.5 (medium), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-200 (3). Most affected products: froxlor/froxlor (7), froxlor (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 12 prev 0
Worst active — by depth score
CVE-2026-90937Critical· 9.9froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives55CVE-2024-58383High· 7.3Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password52CVE-2026-62988Critical· 9.0Froxlor is open source server administration software50CVE-2026-90767Medium· 6.5Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files48CVE-2026-54347High· 8.7Froxlor is open source server administration software48
froxlor vulnerabilities
CVEs affecting froxlor, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2024-58383High· 7.3PoCFroxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password
Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. O…
CVE-2026-90937Critical· 9.9froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives
froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal new…
CVE-2026-90936Medium· 4.3PoCFroxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php
Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying a…
CVE-2026-90935Medium· 4.3PoCFroxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command
Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on for…
CVE-2026-90767Medium· 6.5PoCFroxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with opti…
CVE-2026-54347High· 8.7Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content…
CVE-2026-54348High· 7.2Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.i…
CVE-2026-54543Medium· 5.4Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab char…
CVE-2026-55593Medium· 6.5Froxlor is open source server administration software
Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a v…
CVE-2026-62988Critical· 9.0Froxlor is open source server administration software
Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxl…
GHSA-mr9h-45p9-fg8hMedium· 4.3Froxlor: Authenticated customers can read other customers' allowed sender aliases
Froxlor: Authenticated customers can read other customers' allowed sender aliases
GHSA-q4rm-m6xh-5pv7Medium· 4.3Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API