VulnSea

froxlor has 12 CVEs on record. Disclosure cadence is accelerating: 12 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 6.5 (medium), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-200 (3). Most affected products: froxlor/froxlor (7), froxlor (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
12 prev 0

Products

  • froxlor/froxlor 7
  • froxlor 5
12
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

froxlor vulnerabilities

CVEs affecting froxlor, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2024-58383High· 7.3PoC
1w ago

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. O…

Midnightfroxlor · froxlorEPSS 0.10%via NVD
CVE-2026-90937Critical· 9.9
1w ago

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal new…

Midnightfroxlor · froxlorEPSS 0.26%via NVD
CVE-2026-90936Medium· 4.3PoC
1w ago

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying a…

Twilightfroxlor · froxlorEPSS 0.23%via NVD
CVE-2026-90935Medium· 4.3PoC
1w ago

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on for…

Twilightfroxlor · froxlorEPSS 0.21%via NVD
CVE-2026-90767Medium· 6.5PoC
1w ago

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with opti…

Twilightfroxlor · FroxlorEPSS 0.25%via NVD
CVE-2026-54347High· 8.7
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the content…

Twilightfroxlor · froxlor/froxlorEPSS 0.38%via NVD
CVE-2026-54348High· 7.2
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.i…

Twilightfroxlor · froxlor/froxlorEPSS 0.71%via NVD
CVE-2026-54543Medium· 5.4
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab char…

Sunlitfroxlor · froxlor/froxlorEPSS 0.43%via NVD
CVE-2026-55593Medium· 6.5
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a v…

Sunlitfroxlor · froxlor/froxlorEPSS 0.23%via NVD
CVE-2026-62988Critical· 9.0
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxl…

Midnightfroxlor · froxlor/froxlorEPSS 0.68%via NVD
GHSA-mr9h-45p9-fg8hMedium· 4.3
2mo ago

Froxlor: Authenticated customers can read other customers' allowed sender aliases

Froxlor: Authenticated customers can read other customers' allowed sender aliases

Sunlitfroxlor · froxlor/froxlorvia GHSA
GHSA-q4rm-m6xh-5pv7Medium· 4.3
2mo ago

Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API

Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API

Sunlitfroxlor · froxlor/froxlorvia GHSA
froxlor vulnerabilities (CVEs) · VulnSea