Froxlor/froxlor
50 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Froxlor/froxlor, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Froxlor/froxlor CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 6 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 2 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 50 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical7
- High12
- Medium20
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Froxlor/froxlor.
- GHSA-q4rm-m6xh-5pv7Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API—
- GHSA-mr9h-45p9-fg8hFroxlor: Authenticated customers can read other customers' allowed sender aliases—
- GHSA-f9rx-7wf7-jr36Froxlor's API Authentication bypasses 2FA Authentication—
- GHSA-w59f-67xm-rxx7Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution—
- GHSA-gc9w-cc93-rjv8Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)—
- GHSA-47hf-23pw-3m8cFroxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()—
- GHSA-75h4-c557-j89rFroxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron—
- GHSA-vmjj-qr7v-pxm6Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing—
- GHSA-jvx4-xv3m-hrj4Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()—
- CVE-2026-26279Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection9.1
- CVE-2025-48958Froxlor has an HTML Injection Vulnerability5.5
- CVE-2025-29773Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover5.8
- GHSA-34qg-65m4-f23mFroxlor: /etc/pure-ftpd/db/mysql.conf is chmod 644 but contains <SQL_UNPRIVILEGED_PASSWORD>—
- CVE-2024-34070Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise9.6
- CVE-2023-50256Froxlor username/surname AND company field Bypass7.5
Product grouping is registry-driven, with AI assist and human review. How it works