Vendor
Froxlor vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in Froxlor: 13 in the last 7 days and 25 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100720, was published on 26 September 2026. 1 technology has a page of its own.
- Last 7 days
- 13
- Last 90 days
- 25
- Critical, all time
- 6
- Exploited in the wild
- 0
About Froxlor
Froxlor is an open-source server management panel for Linux distributions.
Froxlor technologies
- Froxlor17
Latest Froxlor vulnerabilities
- CVE-2026-100720: Froxlor stored cross-site scripting in SSL certificate issuerhighCVSS 8.7
- CVE-2026-100719: Froxlor credential disclosure in DirProtections.listing APImediumCVSS 6.5
- CVE-2026-100718: Froxlor API policy bypass in EmailSender.addhighCVSS 7.1
- CVE-2026-100717: froxlor CRLF injection in subdomain redirect validationcriticalCVSS 9.9
- CVE-2026-100716: Froxlor server administration panel symlink path traversal privilege escalationcriticalCVSS 9.9
- CVE-2026-100715: Froxlor arbitrary file deletion via symlink following in cron taskcriticalCVSS 9.6
- CVE-2026-100714: Froxlor argument injection in Let's Encrypt challenge path settingcriticalCVSS 9.1
- CVE-2026-100713: Froxlor SSH key synchronization race condition leading to root accesshighCVSS 7.8
- CVE-2026-100712: froxlor two-factor authentication disable via CSRF GET requestmediumCVSS 6.5
- CVE-2026-100711: froxlor session invalidation bypass on password changehighCVSS 7.5
- CVE-2026-100710: Froxlor information disclosure of DKIM private key via APImediumCVSS 4.9
- CVE-2026-100709: Froxlor TOTP bypass via 2FA token namespace confusionhighCVSS 7.5
- CVE-2026-100708: Froxlor information disclosure in Certificates APIhighCVSS 7.1
- CVE-2026-90937: froxlor CRLF injection in subdomain redirect URLscriticalCVSS 9.9EPSS 0.4%
- CVE-2026-90936: Froxlor information disclosure in sender alias lookupsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-90935: Froxlor authorization bypass in Mysqls.add APImediumCVSS 4.3EPSS 0.3%
- CVE-2024-58383: Froxlor insecure file permissions in pure-ftpd MySQL configurationhighCVSS 7.3EPSS 0.1%
- CVE-2026-90767: Froxlor SSH public key injection in SshKeys::add()mediumCVSS 6.5EPSS 0.4%
- CVE-2026-62988: Froxlor API credential and 2FA secret disclosurecriticalCVSS 9EPSS 0.6%
- CVE-2026-55593: Froxlor CSRF vulnerability in AJAX endpointmediumCVSS 6.5EPSS 0.3%
- CVE-2026-54543: Froxlor DomainZones.add DNS zone-file injectionmediumCVSS 5.4EPSS 0.4%
- CVE-2026-54348: Froxlor second-order SQL injection in IpsAndPorts.listinghighCVSS 7.2EPSS 0.7%
- CVE-2026-54347: Froxlor stored XSS in DNS editor via TXT recordshighCVSS 8.7EPSS 0.4%
- Froxlor authorization bypass in Mysqls.add APImediumCVSS 4.3
- Froxlor information disclosure in sender alias delete confirmationmediumCVSS 4.3
Most severe Froxlor vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-90937: froxlor CRLF injection in subdomain redirect URLscriticalCVSS 9.9EPSS 0.4%
- CVE-2026-100717: froxlor CRLF injection in subdomain redirect validationcriticalCVSS 9.9
- CVE-2026-100716: Froxlor server administration panel symlink path traversal privilege escalationcriticalCVSS 9.9
- CVE-2026-100715: Froxlor arbitrary file deletion via symlink following in cron taskcriticalCVSS 9.6
- CVE-2026-100714: Froxlor argument injection in Let's Encrypt challenge path settingcriticalCVSS 9.1
- CVE-2026-62988: Froxlor API credential and 2FA secret disclosurecriticalCVSS 9EPSS 0.6%
- CVE-2026-41236: Froxlor privilege escalation via symlink following in SSH key synchighCVSS 8.8
- CVE-2026-41235: Froxlor incorrect authorization in FTP shell assignmenthighCVSS 8.8
- CVE-2026-54347: Froxlor stored XSS in DNS editor via TXT recordshighCVSS 8.7EPSS 0.4%
- CVE-2026-100720: Froxlor stored cross-site scripting in SSL certificate issuerhighCVSS 8.7
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 4 | 1 | |
| 21 Sep 2026 | 13 | 4 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/froxlor.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Froxlor vulnerabilities", https://junglewise.ai/threats/vendors/froxlor, 26 September 2026.