Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

froxlor — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in froxlor, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities associated with the Froxlor web server administration software. It serves as a comprehensive resource for tracking weaknesses in this specific vendor’s product line, covering a broad spectrum of vulnerability types that have been identified and disclosed over time. The content aggregates data on various security flaws, ranging from remote code execution and privilege escalation to information disclosure and cross-site scripting issues. These entries encompass incidents reported over the last several years, ensuring that both historical and recent threats are captured for thorough analysis. Users can utilize this resource to track the vendor's security advisories and monitor how quickly Froxlor responds to emerging threats. The page also allows users to understand specific weakness classes by examining real-world examples within the context of this software, helping administrators identify patterns in code quality and security implementation. Furthermore, individuals can look up the product’s vulnerability history to assess its long-term security posture and make informed decisions about deployment or remediation. By consolidating these details, the page provides a clear view of the evolving risk landscape for Froxlor. This structured approach facilitates better security planning and risk management for system administrators and security researchers alike. The information presented is intended to support transparency and enable proactive mitigation strategies based on documented historical data.

Vendor: Froxlor

CVE IDTitleCVSSSeverityPublished
CVE-2026-41237 Froxlor has an incomplete fix for CVE-2026-30932 CWE-74--2026-06-04
CVE-2026-41236 Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path CWE-59 8.8 High2026-06-04
CVE-2026-41235 Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement CWE-863--2026-06-04
CVE-2026-41234 Froxlor: BIND Zone File Injection via TXT Record Content CWE-74 7.6 High2026-06-04
CVE-2026-41233 Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add() CWE-863 5.4 Medium2026-04-23
CVE-2026-41232 Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email Spoofing CWE-863 5.0 Medium2026-04-23
CVE-2026-41231 Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron CWE-59 7.5 High2026-04-23
CVE-2026-41230 Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add() CWE-93 8.5 High2026-04-23
CVE-2026-41229 Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API) CWE-94 9.1 Critical2026-04-23
CVE-2026-41228 Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution CWE-98 10.0 Critical2026-04-23
CVE-2026-30932 Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API CWE-74 7.5 -2026-03-24
CVE-2026-26279 Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection CWE-78 9.1 Critical2026-03-03
CVE-2025-48958 Froxlor has an HTML Injection Vulnerability CWE-79 5.5 Medium2025-06-02
CVE-2025-29773 Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover CWE-287 5.8 Medium2025-03-13
CVE-2024-34070 Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise CWE-79 9.7 Critical2024-05-10
CVE-2023-50256 Froxlor username/surname AND company field Bypass CWE-20 7.5 High2024-01-03

All 16 known CVE vulnerabilities affecting froxlor with full Chinese analysis, references, and POCs where available.