Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Froxlor

First CVE: Feb 13, 2017Active for: 9 yearsTotal CVEs: 47
54.3
VTI Score
TOP TARGET

Froxlor is a web-hosting control panel and server management application whose vulnerability profile, while concentrated in a single widely deployed product, has skewed toward serious outcomes including critical-severity flaws. The exposure clusters around input-validation and output-encoding weaknesses endemic to web-facing administrative interfaces: cross-site scripting, code injection, cross-site request forgery, and improper output escaping recur across the vendor's disclosures and reflect the challenges of sanitizing and validating user input in dynamic web applications. A moderate tendency toward public exploit availability characterizes these vulnerabilities, consistent with the appeal of control-panel compromise for establishing persistence or lateral movement in compromised hosting environments. Defenders operating Froxlor instances should prioritize timely updates and restrict administrative access to trusted networks; live exploitation status, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
47
Total CVEs
More Total CVEs than 98% of tracked vendors
5.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Froxlor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2017
9 years ago
Most Recent CVE
Apr 23, 2026
92 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0315HIGH
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
Jan 16, 20238.890NOYES
CVE-2023-2034HIGH
Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
Apr 14, 20238.868NONO
CVE-2021-42325CRITICAL
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
Oct 12, 20219.848NOYES
CVE-2026-41228CRITICAL
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language
Apr 23, 20269.933NONO
CVE-2022-3869MEDIUM
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
Nov 5, 20226.132NOYES
CVE-2026-26279CRITICAL
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all
Mar 3, 20269.131NONO
CVE-2023-1307CRITICAL
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
Mar 10, 20239.831NONO
CVE-2026-41229CRITICAL
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without
Apr 23, 20269.130NONO
CVE-2026-30932HIGH
Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the con
Mar 24, 20268.830NONO
CVE-2023-3173CRITICAL
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
Jun 9, 20239.829NONO
View all 47 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products47 CVEs
43%
38%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (8.5%)
Network43 (91.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (97.9%)
High1 (2.1%)
Unknown0 (0.0%)
User Interaction
None35 (74.5%)
Unknown0 (0.0%)
Required12 (25.5%)
Privileges Required
Low23 (48.9%)
High9 (19.1%)
None15 (31.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.1% of CVEs· 97th percentile
Nuclei
1 CVE
2.1% of CVEs· 95th percentile
ExploitDB
2 CVEs
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Froxlor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Froxlor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Froxlor's Products

View all 3 CNAs →

Top CWEs