Package impact

php Packagist / froxlor/froxlor

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2016-5100 critical 9.8 9.8 9y ago Froxlor guessable password reset token php
CVE-2026-41228 unknown 1mo ago Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution php
CVE-2026-41229 unknown 1mo ago Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API) php
CVE-2026-41230 unknown 1mo ago Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add() php
CVE-2026-41231 unknown 1mo ago Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron php
CVE-2026-41232 unknown 1mo ago Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing php
CVE-2026-41233 unknown 1mo ago Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add() php
CVE-2026-30932 unknown 2mo ago Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API php
CVE-2026-26279 unknown 3mo ago Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection php
CVE-2025-48958 unknown 1y ago Froxlor has an HTML Injection Vulnerability php
CVE-2025-29773 unknown 1y ago Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover php
CVE-2024-34070 unknown 2y ago Blind XSS Leading to Froxlor Application Compromise php
CVE-2023-50256 unknown 2y ago Froxlor username/surname AND company field Bypass php
CVE-2023-6069 unknown 3y ago Froxlor Improper Input Validation vulnerability php
CVE-2023-4829 unknown 3y ago Cross-site Scripting (XSS) in froxlor/froxlor php
CVE-2023-5564 unknown 3y ago Cross-site Scripting (XSS) in froxlor/froxlor php
CVE-2023-4304 unknown 3y ago Froxlor vulnerable to business logic errors php
CVE-2023-3668 unknown 3y ago Froxlor vulnerable to Improper Encoding or Escaping of Output php
CVE-2023-3192 unknown 3y ago Froxlor Session Fixation vulnerability php
CVE-2023-3173 unknown 3y ago Froxlor vulnerable to Improper Restriction of Excessive Authentication Attempts php
CVE-2023-3172 unknown 3y ago Froxlor vulnerable to Path Traversal php
CVE-2023-2666 unknown 3y ago Froxlor vulnerable to Allocation of Resources Without Limits or Throttling php
CVE-2023-2034 unknown 3y ago froxlor/froxlor vulnerable to unrestricted upload of file with dangerous type php
CVE-2023-1307 unknown 3y ago Froxlor is vulnerable to authentication bypass php
CVE-2023-1033 unknown 3y ago Froxlor Cross-Site Request Forgery vulnerability php
CVE-2023-0877 unknown 3y ago Code Injection in froxlor/froxlor php
CVE-2023-0671 unknown 3y ago froxlor is vulnerable to privilege escalation from customer to root via directory-options php
CVE-2023-0566 unknown 3y ago Froxlor contains Static Code Injection php
CVE-2023-0565 unknown 3y ago Froxlor contains Business Logic Errors php
CVE-2023-0572 unknown 3y ago Froxlor contains Unchecked Error Condition php
CVE-2023-0564 unknown 3y ago Froxlor contains Weak Password Requirements php
CVE-2023-0316 unknown 3y ago Froxlor is vulnerable to path traversal php
CVE-2023-0315 unknown 3y ago Froxlor vulnerable to Command Injection php
CVE-2022-4868 unknown 3y ago Froxlor Improper Authorization vulnerability php
CVE-2022-4867 unknown 3y ago Froxlor vulnerable to Cross-Site Request Forgery php
CVE-2022-4864 unknown 3y ago Froxlor vulnerable to Argument Injection php
CVE-2022-3869 unknown 4y ago Froxlor vulnerable to code injection php
CVE-2022-3721 unknown 4y ago Froxlor vulnerable to Code Injection php
CVE-2022-3017 unknown 4y ago Froxlor vulnerable to Cross-Site Request Forgery (CSRF) php
CVE-2020-28957 unknown 4y ago Foxlor cross-site scripting (XSS) vulnerability php
CVE-2021-42325 unknown 4y ago Froxlor SQL injection vulnerability php
CVE-2020-10237 unknown 4y ago Froxlor Exposure of Sensitive Information to an Unauthorized Actor php
CVE-2020-10236 unknown 4y ago Froxlor Information Disclosure php
CVE-2020-10235 unknown 4y ago Froxlor arbitrary code execution via the database configuration options php
CVE-2018-12642 unknown 4y ago Froxlor Incorrect Access Control php
CVE-2018-1000527 unknown 4y ago Froxlor PHP Object Injection vulnerability php
CVE-2020-29653 unknown 4y ago HTML Injection in Froxlor php