froxlor records
48 published records for vendor froxlor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.1%
- Pre-auth RCE
- 1
- With a fix record
- 91.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-863 Incorrect Authorization2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-840 Business Logic Errors2
The weakness classes this vendor ships most often: where to look.
CWEAll records
48 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2023-0315Weaponized | Command Injection in froxlor/froxlorfroxlor · froxlor · CWE-77 | High8.8 | — | 97.7% | Jan 15, 2023 |
56Plan | CVE-2023-2034No exploit | Unrestricted Upload of File with Dangerous Type in froxlor/froxlorfroxlor · froxlor · CWE-434 | High8.8 | — | 71.4% | Apr 13, 2023 |
43Plan | CVE-2021-42325Proof of concept | Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.froxlor · froxlor · CWE-89 | Critical9.8 | — | 11.8% | Oct 12, 2021 |
40Plan | CVE-2015-5959No exploit | Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sfroxlor · froxlor · CWE-200 | Critical9.8 | — | 3.1% | Sep 6, 2017 |
40Plan | CVE-2016-5100No exploit | Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passwfroxlor · froxlor · CWE-330 | Critical9.8 | — | 1.9% | Feb 13, 2017 |
39Monitor | CVE-2023-3173No exploit | Improper Restriction of Excessive Authentication Attempts in froxlor/froxlorfroxlor · froxlor · CWE-307 | Critical9.8 | — | 1.1% | Jun 8, 2023 |
39Monitor | CVE-2023-1307No exploit | Authentication Bypass by Primary Weakness in froxlor/froxlorfroxlor · froxlor · CWE-305 | Critical9.8 | — | 1.1% | Mar 9, 2023 |
39Monitor | CVE-2026-41228No exploit | Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Executionfroxlor · froxlor · CWE-98 | Critical9.9 | — | 0.7% | Apr 23, 2026 |
38Monitor | CVE-2024-34070Proof of concept | Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromisefroxlor · froxlor · CWE-79 | Critical9.6 | — | 1.0% | May 14, 2024 |
36Monitor | CVE-2023-0877No exploit | Code Injection in froxlor/froxlorfroxlor · froxlor · CWE-94 | High8.8 | — | 3.9% | Feb 16, 2023 |
36Monitor | CVE-2020-10235No exploit | An issue was discovered in Froxlor before 0.10.14.froxlor · froxlor · CWE-78 | High8.8 | — | 1.7% | Mar 9, 2020 |
36Monitor | CVE-2026-26279No exploit | Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injectionfroxlor · froxlor · CWE-78 | Critical9.1 | — | 1.1% | Mar 3, 2026 |
36Monitor | CVE-2026-41229No exploit | Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)froxlor · froxlor · CWE-94 | Critical9.1 | — | 0.7% | Apr 23, 2026 |
35Monitor | CVE-2023-0671No exploit | Code Injection in froxlor/froxlorfroxlor · froxlor · CWE-94 | High8.8 | — | 1.1% | Feb 3, 2023 |
35Monitor | CVE-2023-6069No exploit | Improper Link Resolution Before File Access in froxlor/froxlorfroxlor · froxlor · CWE-59 | High8.8 | — | 0.8% | Nov 9, 2023 |
35Monitor | CVE-2023-1033No exploit | Cross-Site Request Forgery (CSRF) in froxlor/froxlorfroxlor · froxlor · CWE-352 | High8.8 | — | 0.3% | Feb 24, 2023 |
34Monitor | CVE-2026-30932No exploit | Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones APIfroxlor · froxlor · CWE-74 | High8.6 | — | 0.7% | Mar 24, 2026 |
34Monitor | CVE-2026-41230No exploit | Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()froxlor · froxlor · CWE-93 | High8.5 | — | 0.5% | Apr 23, 2026 |
31Monitor | CVE-2025-29773No exploit | Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeoverfroxlor · froxlor · CWE-287 | High7.8 | — | 0.3% | Mar 13, 2025 |
30Monitor | CVE-2018-12642No exploit | Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.froxlor · froxlor · CWE-732 | High7.5 | — | 1.4% | Jun 22, 2018 |
30Monitor | CVE-2023-50256No exploit | Froxlor username/surname AND company field Bypassfroxlor · froxlor · CWE-20 | High7.5 | — | 0.7% | Jan 3, 2024 |
30Monitor | CVE-2023-2666No exploit | Allocation of Resources Without Limits or Throttling in froxlor/froxlorfroxlor · froxlor · CWE-770 | High7.5 | — | 0.7% | May 11, 2023 |
30Monitor | CVE-2026-41231No exploit | Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cronfroxlor · froxlor · CWE-59 | High7.5 | — | 0.5% | Apr 23, 2026 |
30Monitor | CVE-2023-0564No exploit | Weak Password Requirements in froxlor/froxlorfroxlor · froxlor · CWE-521 | High7.5 | — | 0.5% | Jan 28, 2023 |
29Monitor | CVE-2018-1000527No exploit | Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclofroxlor · froxlor · CWE-502 | High7.2 | — | 2.6% | Jun 26, 2018 |
- CVE-2023-031564This week
Command Injection in froxlor/froxlor
HighCVSS 8.8WeaponizedEPSS 98%froxlor · froxlorJan 15, 2023
- CVE-2023-203456Plan
Unrestricted Upload of File with Dangerous Type in froxlor/froxlor
HighCVSS 8.8No exploitEPSS 71%froxlor · froxlorApr 13, 2023
- CVE-2021-4232543Plan
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
CriticalCVSS 9.8Proof of conceptEPSS 12%froxlor · froxlorOct 12, 2021
- CVE-2015-595940Plan
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/s
CriticalCVSS 9.8No exploitEPSS 3%froxlor · froxlorSep 6, 2017
- CVE-2016-510040Plan
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passw
CriticalCVSS 9.8No exploitEPSS 2%froxlor · froxlorFeb 13, 2017
- CVE-2023-317339Monitor
Improper Restriction of Excessive Authentication Attempts in froxlor/froxlor
CriticalCVSS 9.8No exploitEPSS 1%froxlor · froxlorJun 8, 2023
- CVE-2023-130739Monitor
Authentication Bypass by Primary Weakness in froxlor/froxlor
CriticalCVSS 9.8No exploitEPSS 1%froxlor · froxlorMar 9, 2023
- CVE-2026-4122839Monitor
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution
CriticalCVSS 9.9No exploitEPSS 1%froxlor · froxlorApr 23, 2026
- CVE-2024-3407038Monitor
Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise
CriticalCVSS 9.6Proof of conceptEPSS 1%froxlor · froxlorMay 14, 2024
- CVE-2023-087736Monitor
Code Injection in froxlor/froxlor
HighCVSS 8.8No exploitEPSS 4%froxlor · froxlorFeb 16, 2023
- CVE-2020-1023536Monitor
An issue was discovered in Froxlor before 0.10.14.
HighCVSS 8.8No exploitEPSS 2%froxlor · froxlorMar 9, 2020
- CVE-2026-2627936Monitor
Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection
CriticalCVSS 9.1No exploitEPSS 1%froxlor · froxlorMar 3, 2026
- CVE-2026-4122936Monitor
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
CriticalCVSS 9.1No exploitEPSS 1%froxlor · froxlorApr 23, 2026
- CVE-2023-067135Monitor
Code Injection in froxlor/froxlor
HighCVSS 8.8No exploitEPSS 1%froxlor · froxlorFeb 3, 2023
- CVE-2023-606935Monitor
Improper Link Resolution Before File Access in froxlor/froxlor
HighCVSS 8.8No exploitEPSS 1%froxlor · froxlorNov 9, 2023
- CVE-2023-103335Monitor
Cross-Site Request Forgery (CSRF) in froxlor/froxlor
HighCVSS 8.8No exploitEPSS 0%froxlor · froxlorFeb 24, 2023
- CVE-2026-3093234Monitor
Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API
HighCVSS 8.6No exploitEPSS 1%froxlor · froxlorMar 24, 2026
- CVE-2026-4123034Monitor
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
HighCVSS 8.5No exploitEPSS 1%froxlor · froxlorApr 23, 2026
- CVE-2025-2977331Monitor
Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
HighCVSS 7.8No exploitEPSS 0%froxlor · froxlorMar 13, 2025
- CVE-2018-1264230Monitor
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
HighCVSS 7.5No exploitEPSS 1%froxlor · froxlorJun 22, 2018
- CVE-2023-5025630Monitor
Froxlor username/surname AND company field Bypass
HighCVSS 7.5No exploitEPSS 1%froxlor · froxlorJan 3, 2024
- CVE-2023-266630Monitor
Allocation of Resources Without Limits or Throttling in froxlor/froxlor
HighCVSS 7.5No exploitEPSS 1%froxlor · froxlorMay 11, 2023
- CVE-2026-4123130Monitor
Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron
HighCVSS 7.5No exploitEPSS 1%froxlor · froxlorApr 23, 2026
- CVE-2023-056430Monitor
Weak Password Requirements in froxlor/froxlor
HighCVSS 7.5No exploitEPSS 0%froxlor · froxlorJan 28, 2023
- CVE-2018-100052729Monitor
Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclo
HighCVSS 7.2No exploitEPSS 3%froxlor · froxlorJun 26, 2018