Angry Frog maintains a narrow product portfolio centered on the Xavier product, which appears more prominent in vulnerability disclosures than its overall footprint might suggest. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Angry Frog over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15949HIGH Xavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to admin/editgroup.php. | Oct 28, 2017 | 7.2 | 23 | NO | NO |
CVE-2019-14228MEDIUM Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an | Jul 26, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Angry Frog.
Media articles that mention a CVE ID that affects a product developed by Angry Frog — matched by CVE ID, not by vendor name.