CVE Browser
Froxlor before 2.3.12 Stored XSS via SSL certificate issuer
Froxlor before 2.3.12 Credential Disclosure via DirProtections API
Froxlor before 2.3.12 Authentication Bypass via EmailSender.add
froxlor before 2.3.12 CRLF Injection via validateUrl userinfo
Froxlor before 2.3.12 Privilege Escalation via Symlink
Froxlor before 2.3.12 Arbitrary File Deletion via Symlink
Froxlor before 2.3.12 Command Injection via letsencryptchallengepath
Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync
froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF
froxlor before 2.3.12 Authentication Bypass via Session Persistence
Froxlor before 2.3.12 DKIM Private Key Disclosure via API
Froxlor before 2.3.12 2FA Bypass via Namespace Confusion
Froxlor before 2.3.13 Private Key Disclosure via Certificates API
froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL
Froxlor before 2.3.7 Information Disclosure via customer_email.php
Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API
Froxlor before 2.2.0 Insecure File Permissions mysql.conf
Froxlor before 2.3.12 SSH Key Injection via authorized_keys
Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery Protection
Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover
Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration
Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
Froxlor: API Authentication bypasses 2FA Authentication
Froxlor has an incomplete fix for CVE-2026-30932
Showing 1 to 25 CVEs · page 1 (more available)