Technology · Packagist
froxlor/froxlor (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 18 vulnerabilities in froxlor/froxlor (Packagist): 0 in the last 7 days and 7 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-62988, was published on 18 August 2026.
- Last 7 days
- 0
- Last 90 days
- 7
- Critical, all time
- 3
- Exploited in the wild
- 0
About froxlor/froxlor (Packagist)
Froxlor is an open-source server administration control panel for managing web hosting environments.
Latest froxlor/froxlor (Packagist) vulnerabilities
- CVE-2026-62988: Froxlor API credential and 2FA secret disclosurecriticalCVSS 9EPSS 0.6%
- CVE-2026-55593: Froxlor CSRF vulnerability in AJAX endpointmediumCVSS 6.5EPSS 0.3%
- CVE-2026-54543: Froxlor DomainZones.add DNS zone-file injectionmediumCVSS 5.4EPSS 0.4%
- CVE-2026-54348: Froxlor second-order SQL injection in IpsAndPorts.listinghighCVSS 7.2EPSS 0.7%
- CVE-2026-54347: Froxlor stored XSS in DNS editor via TXT recordshighCVSS 8.7EPSS 0.4%
- Froxlor authorization bypass in Mysqls.add APImediumCVSS 4.3
- Froxlor information disclosure in sender alias delete confirmationmediumCVSS 4.3
- CVE-2026-41237: Froxlor DNS zone file injection via improper record validationmediumCVSS 6.5
- CVE-2026-41236: Froxlor privilege escalation via symlink following in SSH key synchighCVSS 8.8
- CVE-2026-41235: Froxlor incorrect authorization in FTP shell assignmenthighCVSS 8.8
- CVE-2026-41234: Froxlor BIND zone file injection in DomainZones API TXT recordshighCVSS 7.6
- Froxlor API two-factor authentication bypasshighCVSS 8.1
- CVE-2026-41228: Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code ExecutioncriticalCVSS 9.9
- CVE-2026-41229: Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)criticalCVSS 9.1
- CVE-2026-41230: Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()highCVSS 8.5
- CVE-2026-41231: Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via CronhighCVSS 7.5
- CVE-2026-41232: Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email SpoofingmediumCVSS 5
- CVE-2026-41233: Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()mediumCVSS 5.4
Most severe froxlor/froxlor (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-41228: Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code ExecutioncriticalCVSS 9.9
- CVE-2026-41229: Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)criticalCVSS 9.1
- CVE-2026-62988: Froxlor API credential and 2FA secret disclosurecriticalCVSS 9EPSS 0.6%
- CVE-2026-41236: Froxlor privilege escalation via symlink following in SSH key synchighCVSS 8.8
- CVE-2026-41235: Froxlor incorrect authorization in FTP shell assignmenthighCVSS 8.8
- CVE-2026-54347: Froxlor stored XSS in DNS editor via TXT recordshighCVSS 8.7EPSS 0.4%
- CVE-2026-41230: Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()highCVSS 8.5
- Froxlor API two-factor authentication bypasshighCVSS 8.1
- CVE-2026-41234: Froxlor BIND zone file injection in DomainZones API TXT recordshighCVSS 7.6
- CVE-2026-41231: Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via CronhighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/froxlor-froxlor.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "froxlor/froxlor (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/froxlor-froxlor, 26 September 2026.