📦 Froxlor

by Froxlor

🔍 What is Froxlor?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-26279

CRITICAL CVSS 9.1 Mar 3, 2026

A typo in Froxlor's input validation code (== instead of =) disables email format checking for admin email settings. This allows authenticated admins to inject arbitrary strings into a root-level cron...

CVE-2023-3173

CRITICAL CVSS 9.8 Jun 9, 2023

CVE-2023-3173 is an authentication brute-force vulnerability in froxlor web hosting control panel. Attackers can bypass rate limiting to perform unlimited login attempts, potentially compromising admi...

CVE-2023-1307

CRITICAL CVSS 9.8 Mar 10, 2023

CVE-2023-1307 is an authentication bypass vulnerability in the Froxlor server management panel that allows attackers to gain unauthorized administrative access without valid credentials. This affects ...

CVE-2021-42325

CRITICAL CVSS 9.8 Oct 12, 2021

CVE-2021-42325 is a SQL injection vulnerability in Froxlor's database management component that allows attackers to execute arbitrary SQL commands via a specially crafted database name. This affects F...

CVE-2023-50256

HIGH CVSS 7.5 Jan 3, 2024

This vulnerability in Froxlor server administration software allows attackers to bypass mandatory field validation during user registration by submitting blank username and password fields. This affec...

CVE-2023-3668

HIGH CVSS 7.2 Jul 14, 2023

CVE-2023-3668 is an improper output encoding vulnerability in the Froxlor server management panel that allows cross-site scripting (XSS) attacks. Attackers can inject malicious scripts that execute in...

CVE-2023-3172

HIGH CVSS 7.2 Jun 9, 2023

This CVE describes a path traversal vulnerability in the Froxlor server management panel that allows attackers to access files outside the intended directory. It affects all Froxlor installations prio...

CVE-2023-2666

HIGH CVSS 7.5 May 12, 2023

CVE-2023-2666 is an allocation of resources without limits vulnerability in Froxlor server management panel. Attackers can cause resource exhaustion (memory/CPU) by sending specially crafted requests,...

CVE-2023-0877

HIGH CVSS 8.8 Feb 17, 2023

CVE-2023-0877 is a code injection vulnerability in the Froxlor server management panel that allows authenticated attackers to execute arbitrary code on affected systems. This affects all Froxlor insta...

CVE-2023-0671

HIGH CVSS 8.8 Feb 4, 2023

This CVE describes a code injection vulnerability in the Froxlor server management panel that allows attackers to execute arbitrary code on affected systems. The vulnerability affects all Froxlor inst...