Froxlor/froxlor
This hub aggregates every CVE we track for Froxlor/froxlor, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
50
CVEs tracked
7
Critical
12
High
0
In CISA KEV
Severity distribution
MEDIUM20HIGH12CRITICAL7LOW1
Monthly trend
0
0
0
0
0
1
0
0
1
0
0
0
0
0
0
0
0
1
6
0
1
2
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Froxlor/froxlor.
- GHSA-q4rm-m6xh-5pv7Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
- GHSA-mr9h-45p9-fg8hFroxlor: Authenticated customers can read other customers' allowed sender aliases
- GHSA-f9rx-7wf7-jr36Froxlor's API Authentication bypasses 2FA Authentication
- GHSA-w59f-67xm-rxx7Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution
- GHSA-gc9w-cc93-rjv8Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
- GHSA-47hf-23pw-3m8cFroxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
- GHSA-75h4-c557-j89rFroxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron
- GHSA-vmjj-qr7v-pxm6Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing
- GHSA-jvx4-xv3m-hrj4Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()
- CVE-2026-26279Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection9.1
- CVE-2025-48958Froxlor has an HTML Injection Vulnerability5.5
- CVE-2025-29773Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover5.8
- GHSA-34qg-65m4-f23mFroxlor: /etc/pure-ftpd/db/mysql.conf is chmod 644 but contains <SQL_UNPRIVILEGED_PASSWORD>
- CVE-2024-34070Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise9.6
- CVE-2023-50256Froxlor username/surname AND company field Bypass7.5
Product normalization is registry-driven with AI assist and human review. How it works