Vulnerabilities in froxlor
54 resultsVexday analysis
Froxlor apresenta 41 vulnerabilidades catalogadas, com 11 em nível crítico e 10 divulgadas nos últimos 90 dias, indicando cadência preocupante de descobertas recentes. A fraqueza dominante é XSS (CWE-79), típica de aplicações web, mas nenhuma vulnerabilidade está em exploração ativa conhecida no momento. O volume recente de críticas demanda atenção prioritária em ciclos de atualização.
CVE-2023-4829MEDIUMCross-site Scripting (XSS) - Stored in froxlor/froxlorEPSS 0.4%CVE-2023-5564MEDIUMCross-site Scripting (XSS) - Stored in froxlor/froxlorEPSS 0.4%CVE-2026-41235HIGHFroxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcementEPSS 0.4%CVE-2022-4867LOWCross-Site Request Forgery (CSRF) in froxlor/froxlorEPSS 0.3%CVE-2020-36978MEDIUMFroxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site ScriptingEPSS 0.3%CVE-2026-41232MEDIUMFroxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index that Allows Cross-Customer Email SpoofingEPSS 0.3%CVE-2025-48958MEDIUMFroxlor has an HTML Injection VulnerabilityEPSS 0.3%CVE-2026-52793HIGHFroxlor: API Authentication bypasses 2FA AuthenticationEPSS 0.3%CVE-2023-1033MEDIUMCross-Site Request Forgery (CSRF) in froxlor/froxlorEPSS 0.3%CVE-2026-90936MEDIUMFroxlor before 2.3.7 Information Disclosure via customer_email.phpEPSS 0.3%CVE-2026-90935MEDIUMFroxlor before 2.3.7 Authorization Bypass via Mysqls.add APIEPSS 0.3%CVE-2025-29773MEDIUMFroxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account TakeoverEPSS 0.3%CVE-2026-55593MEDIUMFroxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery ProtectionEPSS 0.3%CVE-2024-58383HIGHFroxlor before 2.2.0 Insecure File Permissions mysql.confEPSS 0.1%