Froxlor is a web-hosting control panel and server management application whose vulnerability profile, while concentrated in a single widely deployed product, has skewed toward serious outcomes including critical-severity flaws. The exposure clusters around input-validation and output-encoding weaknesses endemic to web-facing administrative interfaces: cross-site scripting, code injection, cross-site request forgery, and improper output escaping recur across the vendor's disclosures and reflect the challenges of sanitizing and validating user input in dynamic web applications. A moderate tendency toward public exploit availability characterizes these vulnerabilities, consistent with the appeal of control-panel compromise for establishing persistence or lateral movement in compromised hosting environments. Defenders operating Froxlor instances should prioritize timely updates and restrict administrative access to trusted networks; live exploitation status, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Froxlor over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0315HIGH Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | Jan 16, 2023 | 8.8 | 90 | NO | YES |
CVE-2023-2034HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14. | Apr 14, 2023 | 8.8 | 68 | NO | NO |
CVE-2021-42325CRITICAL Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name. | Oct 12, 2021 | 9.8 | 48 | NO | YES |
CVE-2026-41228CRITICAL Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language | Apr 23, 2026 | 9.9 | 33 | NO | NO |
CVE-2022-3869MEDIUM Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2. | Nov 5, 2022 | 6.1 | 32 | NO | YES |
CVE-2026-26279CRITICAL Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all | Mar 3, 2026 | 9.1 | 31 | NO | NO |
CVE-2023-1307CRITICAL Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. | Mar 10, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-41229CRITICAL Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without | Apr 23, 2026 | 9.1 | 30 | NO | NO |
CVE-2026-30932HIGH Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the con | Mar 24, 2026 | 8.8 | 30 | NO | NO |
CVE-2023-3173CRITICAL Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20. | Jun 9, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Froxlor.
Media articles that mention a CVE ID that affects a product developed by Froxlor — matched by CVE ID, not by vendor name.