{"schema_version":1,"title":"Froxlor vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 30 vulnerabilities in Froxlor: 13 in the last 7 days and 25 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100720, was published on 26 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/froxlor","json_url":"https://junglewise.ai/threats/vendors/froxlor.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/froxlor","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":13,"all_time":30,"critical":6,"exploited":0,"last_7_days":13,"last_30_days":18,"last_90_days":25,"last_365_days":30},"latest":[{"cve":"CVE-2026-100720","cvss":8.7,"slug":"cve-2026-100720-froxlor-2-0-0-through-2-3-10-is-vulnerable-to-stored-cross-site","title":"Froxlor stored cross-site scripting in SSL certificate issuer","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:58.23+00:00","url":"https://junglewise.ai/threats/cve-2026-100720-froxlor-2-0-0-through-2-3-10-is-vulnerable-to-stored-cross-site"},{"cve":"CVE-2026-100719","cvss":6.5,"slug":"cve-2026-100719-froxlor-versions-before-2-3-12-contain-a-credential-disclosure","title":"Froxlor credential disclosure in DirProtections.listing API","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:58.077+00:00","url":"https://junglewise.ai/threats/cve-2026-100719-froxlor-versions-before-2-3-12-contain-a-credential-disclosure"},{"cve":"CVE-2026-100718","cvss":7.1,"slug":"cve-2026-100718-froxlor-through-2-3-10-does-not-enforce-the-mail-allow-external","title":"Froxlor API policy bypass in EmailSender.add","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:57.917+00:00","url":"https://junglewise.ai/threats/cve-2026-100718-froxlor-through-2-3-10-does-not-enforce-the-mail-allow-external"},{"cve":"CVE-2026-100717","cvss":9.9,"slug":"cve-2026-100717-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and","title":"froxlor CRLF injection in subdomain redirect validation","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.753+00:00","url":"https://junglewise.ai/threats/cve-2026-100717-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and"},{"cve":"CVE-2026-100716","cvss":9.9,"slug":"cve-2026-100716-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and","title":"Froxlor server administration panel symlink path traversal privilege escalation","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.583+00:00","url":"https://junglewise.ai/threats/cve-2026-100716-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and"},{"cve":"CVE-2026-100715","cvss":9.6,"slug":"cve-2026-100715-froxlor-through-2-3-10-is-vulnerable-to-arbitrary-file-deletion","title":"Froxlor arbitrary file deletion via symlink following in cron task","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.427+00:00","url":"https://junglewise.ai/threats/cve-2026-100715-froxlor-through-2-3-10-is-vulnerable-to-arbitrary-file-deletion"},{"cve":"CVE-2026-100714","cvss":9.1,"slug":"cve-2026-100714-froxlor-before-2-3-12-does-not-restrict-or-escape-the-system","title":"Froxlor argument injection in Let's Encrypt challenge path setting","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.24+00:00","url":"https://junglewise.ai/threats/cve-2026-100714-froxlor-before-2-3-12-does-not-restrict-or-escape-the-system"},{"cve":"CVE-2026-100713","cvss":7.8,"slug":"cve-2026-100713-froxlor-2-3-10-and-earlier-contain-a-time-of-check-time-of-use","title":"Froxlor SSH key synchronization race condition leading to root access","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:57.067+00:00","url":"https://junglewise.ai/threats/cve-2026-100713-froxlor-2-3-10-and-earlier-contain-a-time-of-check-time-of-use"},{"cve":"CVE-2026-100712","cvss":6.5,"slug":"cve-2026-100712-froxlor-through-2-3-10-disables-a-user-s-two-factor","title":"froxlor two-factor authentication disable via CSRF GET request","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:56.903+00:00","url":"https://junglewise.ai/threats/cve-2026-100712-froxlor-through-2-3-10-disables-a-user-s-two-factor"},{"cve":"CVE-2026-100711","cvss":7.5,"slug":"cve-2026-100711-froxlor-versions-before-2-3-12-fail-to-invalidate-existing-panel","title":"froxlor session invalidation bypass on password change","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:56.743+00:00","url":"https://junglewise.ai/threats/cve-2026-100711-froxlor-versions-before-2-3-12-fail-to-invalidate-existing-panel"},{"cve":"CVE-2026-100710","cvss":4.9,"slug":"cve-2026-100710-froxlor-through-2-3-10-does-not-filter-sensitive-columns-from","title":"Froxlor information disclosure of DKIM private key via API","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:56.58+00:00","url":"https://junglewise.ai/threats/cve-2026-100710-froxlor-through-2-3-10-does-not-filter-sensitive-columns-from"},{"cve":"CVE-2026-100709","cvss":7.5,"slug":"cve-2026-100709-froxlor-through-2-3-10-stores-only-a-numeric-user-id-in","title":"Froxlor TOTP bypass via 2FA token namespace confusion","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:56.417+00:00","url":"https://junglewise.ai/threats/cve-2026-100709-froxlor-through-2-3-10-stores-only-a-numeric-user-id-in"},{"cve":"CVE-2026-100708","cvss":7.1,"slug":"cve-2026-100708-froxlor-before-2-3-13-returns-the-ssl-key-file-column-which","title":"Froxlor information disclosure in Certificates API","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:56.153+00:00","url":"https://junglewise.ai/threats/cve-2026-100708-froxlor-before-2-3-13-returns-the-ssl-key-file-column-which"},{"cve":"CVE-2026-90937","cvss":9.9,"epss":0.0045,"slug":"cve-2026-90937-froxlor-crlf-injection-in-subdomain-redirect-urls","title":"froxlor CRLF injection in subdomain redirect URLs","severity":"critical","exploited":false,"published_at":"2026-09-14T13:19:32.277+00:00","url":"https://junglewise.ai/threats/cve-2026-90937-froxlor-crlf-injection-in-subdomain-redirect-urls"},{"cve":"CVE-2026-90936","cvss":4.3,"epss":0.0031,"slug":"cve-2026-90936-froxlor-information-disclosure-in-sender-alias-lookups","title":"Froxlor information disclosure in sender alias lookups","severity":"medium","exploited":false,"published_at":"2026-09-14T13:19:32.13+00:00","url":"https://junglewise.ai/threats/cve-2026-90936-froxlor-information-disclosure-in-sender-alias-lookups"},{"cve":"CVE-2026-90935","cvss":4.3,"epss":0.003,"slug":"cve-2026-90935-froxlor-authorization-bypass-in-mysqls-add-api","title":"Froxlor authorization bypass in Mysqls.add API","severity":"medium","exploited":false,"published_at":"2026-09-14T13:19:31.987+00:00","url":"https://junglewise.ai/threats/cve-2026-90935-froxlor-authorization-bypass-in-mysqls-add-api"},{"cve":"CVE-2024-58383","cvss":7.3,"epss":0.001,"slug":"cve-2024-58383-froxlor-insecure-file-permissions-in-pure-ftpd-mysql","title":"Froxlor insecure file permissions in pure-ftpd MySQL configuration","severity":"high","exploited":false,"published_at":"2026-09-14T13:17:15.15+00:00","url":"https://junglewise.ai/threats/cve-2024-58383-froxlor-insecure-file-permissions-in-pure-ftpd-mysql"},{"cve":"CVE-2026-90767","cvss":6.5,"epss":0.0044,"slug":"cve-2026-90767-froxlor-ssh-public-key-injection-in-sshkeys-add","title":"Froxlor SSH public key injection in SshKeys::add()","severity":"medium","exploited":false,"published_at":"2026-09-13T11:17:00.947+00:00","url":"https://junglewise.ai/threats/cve-2026-90767-froxlor-ssh-public-key-injection-in-sshkeys-add"},{"cve":"CVE-2026-62988","cvss":9,"epss":0.0063,"slug":"cve-2026-62988-froxlor-api-credential-and-2fa-secret-disclosure","title":"Froxlor API credential and 2FA secret disclosure","severity":"critical","exploited":false,"published_at":"2026-08-18T20:48:35+00:00","url":"https://junglewise.ai/threats/cve-2026-62988-froxlor-api-credential-and-2fa-secret-disclosure"},{"cve":"CVE-2026-55593","cvss":6.5,"epss":0.0026,"slug":"cve-2026-55593-froxlor-csrf-vulnerability-in-ajax-endpoint","title":"Froxlor CSRF vulnerability in AJAX endpoint","severity":"medium","exploited":false,"published_at":"2026-08-18T20:48:30+00:00","url":"https://junglewise.ai/threats/cve-2026-55593-froxlor-csrf-vulnerability-in-ajax-endpoint"},{"cve":"CVE-2026-54543","cvss":5.4,"epss":0.0045,"slug":"cve-2026-54543-froxlor-domainzones-add-dns-zone-file-injection","title":"Froxlor DomainZones.add DNS zone-file injection","severity":"medium","exploited":false,"published_at":"2026-08-18T20:48:04+00:00","url":"https://junglewise.ai/threats/cve-2026-54543-froxlor-domainzones-add-dns-zone-file-injection"},{"cve":"CVE-2026-54348","cvss":7.2,"epss":0.0066,"slug":"cve-2026-54348-froxlor-second-order-sql-injection-in-ipsandports-listing","title":"Froxlor second-order SQL injection in IpsAndPorts.listing","severity":"high","exploited":false,"published_at":"2026-08-18T20:47:59+00:00","url":"https://junglewise.ai/threats/cve-2026-54348-froxlor-second-order-sql-injection-in-ipsandports-listing"},{"cve":"CVE-2026-54347","cvss":8.7,"epss":0.0042,"slug":"cve-2026-54347-froxlor-stored-xss-in-dns-editor-via-txt-records","title":"Froxlor stored XSS in DNS editor via TXT records","severity":"high","exploited":false,"published_at":"2026-08-18T20:47:53+00:00","url":"https://junglewise.ai/threats/cve-2026-54347-froxlor-stored-xss-in-dns-editor-via-txt-records"},{"cvss":4.3,"slug":"froxlor-authorization-bypass-in-mysqls-add-api-2dea4946","title":"Froxlor authorization bypass in Mysqls.add API","severity":"medium","exploited":false,"published_at":"2026-07-02T19:23:49+00:00","url":"https://junglewise.ai/threats/froxlor-authorization-bypass-in-mysqls-add-api-2dea4946"},{"cvss":4.3,"slug":"froxlor-information-disclosure-in-sender-alias-delete-confirmation-4661365f","title":"Froxlor information disclosure in sender alias delete confirmation","severity":"medium","exploited":false,"published_at":"2026-07-02T19:23:31+00:00","url":"https://junglewise.ai/threats/froxlor-information-disclosure-in-sender-alias-delete-confirmation-4661365f"}],"vendor":{"hub":true,"name":"Froxlor","slug":"froxlor","homepage":"https://froxlor.org/","description":"Froxlor is an open-source server management panel for Linux distributions.","url":"https://junglewise.ai/threats/vendors/froxlor"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":5},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":4,"exploited":0,"vulnerabilities":13}],"most_severe":[{"cve":"CVE-2026-90937","cvss":9.9,"epss":0.0045,"slug":"cve-2026-90937-froxlor-crlf-injection-in-subdomain-redirect-urls","title":"froxlor CRLF injection in subdomain redirect URLs","severity":"critical","exploited":false,"published_at":"2026-09-14T13:19:32.277+00:00","url":"https://junglewise.ai/threats/cve-2026-90937-froxlor-crlf-injection-in-subdomain-redirect-urls"},{"cve":"CVE-2026-100717","cvss":9.9,"slug":"cve-2026-100717-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and","title":"froxlor CRLF injection in subdomain redirect validation","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.753+00:00","url":"https://junglewise.ai/threats/cve-2026-100717-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and"},{"cve":"CVE-2026-100716","cvss":9.9,"slug":"cve-2026-100716-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and","title":"Froxlor server administration panel symlink path traversal privilege escalation","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.583+00:00","url":"https://junglewise.ai/threats/cve-2026-100716-froxlor-is-a-server-administration-panel-in-versions-2-3-10-and"},{"cve":"CVE-2026-100715","cvss":9.6,"slug":"cve-2026-100715-froxlor-through-2-3-10-is-vulnerable-to-arbitrary-file-deletion","title":"Froxlor arbitrary file deletion via symlink following in cron task","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.427+00:00","url":"https://junglewise.ai/threats/cve-2026-100715-froxlor-through-2-3-10-is-vulnerable-to-arbitrary-file-deletion"},{"cve":"CVE-2026-100714","cvss":9.1,"slug":"cve-2026-100714-froxlor-before-2-3-12-does-not-restrict-or-escape-the-system","title":"Froxlor argument injection in Let's Encrypt challenge path setting","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:57.24+00:00","url":"https://junglewise.ai/threats/cve-2026-100714-froxlor-before-2-3-12-does-not-restrict-or-escape-the-system"},{"cve":"CVE-2026-62988","cvss":9,"epss":0.0063,"slug":"cve-2026-62988-froxlor-api-credential-and-2fa-secret-disclosure","title":"Froxlor API credential and 2FA secret disclosure","severity":"critical","exploited":false,"published_at":"2026-08-18T20:48:35+00:00","url":"https://junglewise.ai/threats/cve-2026-62988-froxlor-api-credential-and-2fa-secret-disclosure"},{"cve":"CVE-2026-41236","cvss":8.8,"epss":0.0058,"slug":"cve-2026-41236-froxlor-privilege-escalation-via-symlink-following-in-ssh-key","title":"Froxlor privilege escalation via symlink following in SSH key sync","severity":"high","exploited":false,"published_at":"2026-06-04T19:16:29.327+00:00","url":"https://junglewise.ai/threats/cve-2026-41236-froxlor-privilege-escalation-via-symlink-following-in-ssh-key"},{"cve":"CVE-2026-41235","cvss":8.8,"epss":0.0036,"slug":"cve-2026-41235-froxlor-incorrect-authorization-in-ftp-shell-assignment","title":"Froxlor incorrect authorization in FTP shell assignment","severity":"high","exploited":false,"published_at":"2026-06-04T19:16:29.153+00:00","url":"https://junglewise.ai/threats/cve-2026-41235-froxlor-incorrect-authorization-in-ftp-shell-assignment"},{"cve":"CVE-2026-54347","cvss":8.7,"epss":0.0042,"slug":"cve-2026-54347-froxlor-stored-xss-in-dns-editor-via-txt-records","title":"Froxlor stored XSS in DNS editor via TXT records","severity":"high","exploited":false,"published_at":"2026-08-18T20:47:53+00:00","url":"https://junglewise.ai/threats/cve-2026-54347-froxlor-stored-xss-in-dns-editor-via-txt-records"},{"cve":"CVE-2026-100720","cvss":8.7,"slug":"cve-2026-100720-froxlor-2-0-0-through-2-3-10-is-vulnerable-to-stored-cross-site","title":"Froxlor stored cross-site scripting in SSL certificate issuer","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:58.23+00:00","url":"https://junglewise.ai/threats/cve-2026-100720-froxlor-2-0-0-through-2-3-10-is-vulnerable-to-stored-cross-site"}],"generated_at":"2026-09-26T19:07:00.176898+00:00","technologies":[{"name":"Froxlor","slug":"froxlor","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/froxlor"}]}