Froxlor

18 known vulnerabilities in Froxlor, 4 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100720 CVSS 9.3 critical Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role)…
  • CVE-2026-100719 CVSS 7.1 high Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns…
  • CVE-2026-100718 CVSS 7.1 high Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator…
  • CVE-2026-100717 CVSS 8.5 high froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed…
  • CVE-2026-100716 CVSS 9.4 critical Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate…
  • CVE-2026-100715 CVSS 8.5 high Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8…
  • CVE-2026-100714 CVSS 9.4 critical Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in…
  • CVE-2026-100713 CVSS 7.1 high Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron…
  • CVE-2026-100712 CVSS 7.1 high froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA…
  • CVE-2026-100711 CVSS 8.7 high froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is…
  • CVE-2026-100710 CVSS 6.9 medium Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDomains::get(), and…
  • CVE-2026-100709 CVSS 7.7 high Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace…
  • CVE-2026-100708 CVSS 7.1 high Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses…
  • CVE-2026-90937 CVSS 9.4 critical froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject…
  • CVE-2026-90936 CVSS 5.3 medium Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers…
  • CVE-2026-90935 CVSS 5.3 medium Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API…
  • CVE-2024-58383 CVSS 8.4 high Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML…
  • CVE-2026-90767 CVSS 7.1 high Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject…