CVE Tools

Froxlor/froxlor

50 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Froxlor/froxlor, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Froxlor/froxlor CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Froxlor/froxlor CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-046
2026-050
2026-061
2026-072
2026-080
2026-090

Severity

How the 50 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical718%
  • High1230%
  • Medium2050%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting Froxlor/froxlor.

  1. GHSA-q4rm-m6xh-5pv7Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API—
  2. GHSA-mr9h-45p9-fg8hFroxlor: Authenticated customers can read other customers' allowed sender aliases—
  3. GHSA-f9rx-7wf7-jr36Froxlor's API Authentication bypasses 2FA Authentication—
  4. GHSA-w59f-67xm-rxx7Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution—
  5. GHSA-gc9w-cc93-rjv8Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)—
  6. GHSA-47hf-23pw-3m8cFroxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()—
  7. GHSA-75h4-c557-j89rFroxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron—
  8. GHSA-vmjj-qr7v-pxm6Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing—
  9. GHSA-jvx4-xv3m-hrj4Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()—
  10. CVE-2026-26279Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection9.1
  11. CVE-2025-48958Froxlor has an HTML Injection Vulnerability5.5
  12. CVE-2025-29773Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover5.8
  13. GHSA-34qg-65m4-f23mFroxlor: /etc/pure-ftpd/db/mysql.conf is chmod 644 but contains <SQL_UNPRIVILEGED_PASSWORD>—
  14. CVE-2024-34070Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise9.6
  15. CVE-2023-50256Froxlor username/surname AND company field Bypass7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store