Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Froxlor — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Froxlor, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities associated with the Froxlor web server administration software, categorized by common weakness types and security tags. It aggregates a comprehensive collection of disclosed flaws affecting this specific product, spanning from the earliest reported incidents up to recent updates within the current calendar year. By browsing this resource, you can track vendor advisories to stay informed about critical patches, understand the systemic impact of specific weakness classes on server management interfaces, and look up a product's vulnerability history to assess long-term security trends and remediation patterns. Froxlor, as a popular open-source tool for managing web hosting environments, has been subject to various security reviews, including issues related to cross-site scripting, privilege escalation, and insecure direct object references. This aggregation serves as a centralized reference point for security professionals, system administrators, and developers who need to evaluate the risk posture of their hosting infrastructure. The data is organized to facilitate quick identification of affected versions and the availability of fixes, ensuring that users can efficiently prioritize their maintenance tasks. By providing a chronological and categorical view of these security events, the page helps stakeholders understand not just the isolated incidents, but the broader context of software maturity and ongoing development practices. This information is crucial for maintaining the integrity and confidentiality of web hosting platforms that rely on Froxlor for routine administrative operations.

Vendor: Froxlor

CVE IDTitleCVSSSeverityPublished
CVE-2026-41237 Froxlor has an incomplete fix for CVE-2026-30932 CWE-74--2026-06-04
CVE-2026-41236 Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path CWE-59 8.8 High2026-06-04
CVE-2026-41235 Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement CWE-863--2026-06-04
CVE-2026-41234 Froxlor: BIND Zone File Injection via TXT Record Content CWE-74 7.6 High2026-06-04
CVE-2026-41233 Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add() CWE-863 5.4 Medium2026-04-23
CVE-2026-41232 Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email Spoofing CWE-863 5.0 Medium2026-04-23
CVE-2026-41231 Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron CWE-59 7.5 High2026-04-23
CVE-2026-41230 Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add() CWE-93 8.5 High2026-04-23
CVE-2026-41229 Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API) CWE-94 9.1 Critical2026-04-23
CVE-2026-41228 Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution CWE-98 10.0 Critical2026-04-23
CVE-2026-30932 Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API CWE-74 7.5 -2026-03-24
CVE-2026-26279 Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection CWE-78 9.1 Critical2026-03-03
CVE-2025-48958 Froxlor has an HTML Injection Vulnerability CWE-79 5.5 Medium2025-06-02
CVE-2025-29773 Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover CWE-287 5.8 Medium2025-03-13
CVE-2024-34070 Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise CWE-79 9.7 Critical2024-05-10
CVE-2023-50256 Froxlor username/surname AND company field Bypass CWE-20 7.5 High2024-01-03

All 16 known CVE vulnerabilities affecting Froxlor with full Chinese analysis, references, and POCs where available.