Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

froxlor — Vulnerabilities & Security Advisories 67

Browse all 67 CVE security advisories affecting froxlor. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Froxlor is an open-source web hosting control panel designed to automate the management of web, DNS, mail, and database services for system administrators. Its architecture, primarily built in PHP, has historically exposed it to a significant volume of security flaws, currently totaling 39 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper access controls within its administrative interface. Privilege escalation remains a critical concern, allowing unauthenticated or low-privileged users to gain elevated system access. While no single catastrophic global incident has defined its history, the sheer number of disclosed CVEs indicates systemic weaknesses in code review and security hardening. Administrators relying on this platform must prioritize rigorous patch management and network segmentation to mitigate the risk of exploitation inherent in its long-standing codebase.

CVE ID Title CVSS Severity Published
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer — froxlor CWE-79 8.7 High 2026-09-26
CVE-2026-100719 Froxlor before 2.3.12 Credential Disclosure via DirProtections API — froxlor CWE-200 6.5 Medium 2026-09-26
CVE-2026-100718 Froxlor before 2.3.12 Authentication Bypass via EmailSender.add — froxlor CWE-276 7.1 High 2026-09-26
CVE-2026-100717 froxlor before 2.3.12 CRLF Injection via validateUrl userinfo — froxlor CWE-93 9.9 Critical 2026-09-26
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink — froxlor CWE-59 9.9 Critical 2026-09-26
CVE-2026-100715 Froxlor before 2.3.12 Arbitrary File Deletion via Symlink — froxlor CWE-59 9.6 Critical 2026-09-26
CVE-2026-100713 Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync — froxlor CWE-367 7.8 High 2026-09-26
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath — froxlor CWE-88 9.1 Critical 2026-09-26
CVE-2026-100712 froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF — froxlor CWE-352 6.5 Medium 2026-09-26
CVE-2026-100711 froxlor before 2.3.12 Authentication Bypass via Session Persistence — froxlor CWE-613 7.5 High 2026-09-26
CVE-2026-100710 Froxlor before 2.3.12 DKIM Private Key Disclosure via API — froxlor CWE-200 4.9 Medium 2026-09-26
CVE-2026-100709 Froxlor before 2.3.12 2FA Bypass via Namespace Confusion — froxlor CWE-287 7.5 High 2026-09-26
CVE-2026-100708 Froxlor before 2.3.13 Private Key Disclosure via Certificates API — froxlor CWE-200 7.1 High 2026-09-26
CVE-2026-90936 Froxlor before 2.3.7 Information Disclosure via customer_email.php — froxlor CWE-200 4.3 Medium 2026-09-14
CVE-2026-90937 froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL — froxlor CWE-93 9.9 Critical 2026-09-14
CVE-2026-90935 Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API — froxlor CWE-285 4.3 Medium 2026-09-14
CVE-2024-58383 Froxlor before 2.2.0 Insecure File Permissions mysql.conf — froxlor CWE-732 7.3 High 2026-09-14
CVE-2026-90767 Froxlor before 2.3.12 SSH Key Injection via authorized_keys — Froxlor CWE-93 6.5 Medium 2026-09-13
CVE-2026-55593 Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery Protection — froxlor CWE-352 6.5 Medium 2026-08-18
CVE-2026-54347 Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover — froxlor CWE-79 8.7 High 2026-08-18
CVE-2026-54348 Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration — froxlor CWE-89 7.2 High 2026-08-18
CVE-2026-54543 Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields — froxlor CWE-74 5.4 Medium 2026-08-18
CVE-2026-62988 Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints — froxlor CWE-200 9.0 Critical 2026-08-18
CVE-2026-52793 Froxlor: API Authentication bypasses 2FA Authentication — froxlor CWE-287 8.1 High 2026-08-18
CVE-2026-41237 Froxlor has an incomplete fix for CVE-2026-30932 — froxlor CWE-74 - - 2026-06-04
CVE-2026-41236 Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path — froxlor CWE-59 8.8 High 2026-06-04
CVE-2026-41235 Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement — froxlor CWE-863 - - 2026-06-04
CVE-2026-41234 Froxlor: BIND Zone File Injection via TXT Record Content — froxlor CWE-74 7.6 High 2026-06-04
CVE-2026-41233 Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add() — froxlor CWE-863 5.4 Medium 2026-04-23
CVE-2026-41232 Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email Spoofing — froxlor CWE-863 5.0 Medium 2026-04-23

This page lists every published CVE security advisory associated with froxlor. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.