froxlor CVE Vulnerabilities & Metrics

Focus on froxlor vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About froxlor Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with froxlor. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total froxlor CVEs: 37
Earliest CVE date: 13 Feb 2017, 18:59 UTC
Latest CVE date: 03 Jan 2024, 23:15 UTC

Latest CVE reference: CVE-2023-50256

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical froxlor CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.32

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 30
4.0-6.9 6
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS froxlor CVEs

These are the five CVEs with the highest CVSS scores for froxlor, sorted by severity first and recency.

All CVEs for froxlor

CVE-2023-50256 froxlor vulnerability CVSS: 0 03 Jan 2024, 23:15 UTC

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as the username and password, left intentionally blank. This inadvertent omission allowed for a bypass of the mandatory field requirements (e.g. surname, company name) established by the system. Version 2.1.2 fixes this issue.

CVE-2023-6069 froxlor vulnerability CVSS: 0 10 Nov 2023, 01:15 UTC

Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.

CVE-2023-4829 froxlor vulnerability CVSS: 0 13 Oct 2023, 13:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.

CVE-2023-5564 froxlor vulnerability CVSS: 0 13 Oct 2023, 01:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.

CVE-2023-4304 froxlor vulnerability CVSS: 0 11 Aug 2023, 01:15 UTC

Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

CVE-2023-3668 froxlor vulnerability CVSS: 0 14 Jul 2023, 01:15 UTC

Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.

CVE-2023-3192 froxlor vulnerability CVSS: 0 11 Jun 2023, 11:15 UTC

Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.

CVE-2023-3173 froxlor vulnerability CVSS: 0 09 Jun 2023, 02:15 UTC

Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.

CVE-2023-3172 froxlor vulnerability CVSS: 0 09 Jun 2023, 01:15 UTC

Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

CVE-2023-2666 froxlor vulnerability CVSS: 0 12 May 2023, 01:15 UTC

Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.

CVE-2023-2034 froxlor vulnerability CVSS: 0 14 Apr 2023, 01:15 UTC

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

CVE-2023-1307 froxlor vulnerability CVSS: 0 10 Mar 2023, 01:15 UTC

Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

CVE-2023-1033 froxlor vulnerability CVSS: 0 25 Feb 2023, 01:15 UTC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.

CVE-2023-0877 froxlor vulnerability CVSS: 0 17 Feb 2023, 01:15 UTC

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.

CVE-2023-0671 froxlor vulnerability CVSS: 0 04 Feb 2023, 01:15 UTC

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.

CVE-2023-0572 froxlor vulnerability CVSS: 0 29 Jan 2023, 23:15 UTC

Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10.

CVE-2023-0566 froxlor vulnerability CVSS: 0 29 Jan 2023, 22:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.

CVE-2023-0565 froxlor vulnerability CVSS: 0 29 Jan 2023, 22:15 UTC

Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.

CVE-2023-0564 froxlor vulnerability CVSS: 0 29 Jan 2023, 01:15 UTC

Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.

CVE-2023-0316 froxlor vulnerability CVSS: 0 16 Jan 2023, 01:15 UTC

Path Traversal: '\..\filename' in GitHub repository froxlor/froxlor prior to 2.0.0.

CVE-2023-0315 froxlor vulnerability CVSS: 0 16 Jan 2023, 01:15 UTC

Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

CVE-2022-4868 froxlor vulnerability CVSS: 0 31 Dec 2022, 10:15 UTC

Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

CVE-2022-4867 froxlor vulnerability CVSS: 0 31 Dec 2022, 09:15 UTC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

CVE-2022-4864 froxlor vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

CVE-2022-3869 froxlor vulnerability CVSS: 0 05 Nov 2022, 14:15 UTC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

CVE-2022-3721 froxlor vulnerability CVSS: 0 04 Nov 2022, 13:15 UTC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

CVE-2022-3017 froxlor vulnerability CVSS: 0 28 Aug 2022, 14:15 UTC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

CVE-2020-29653 froxlor vulnerability CVSS: 4.3 13 Apr 2022, 13:15 UTC

Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.

CVE-2020-28957 froxlor vulnerability CVSS: 3.5 22 Oct 2021, 20:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields.

CVE-2021-42325 froxlor vulnerability CVSS: 7.5 12 Oct 2021, 20:15 UTC

Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

CVE-2020-10237 froxlor vulnerability CVSS: 2.1 09 Mar 2020, 16:15 UTC

An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at the right time, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.

CVE-2020-10236 froxlor vulnerability CVSS: 3.6 09 Mar 2020, 16:15 UTC

An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause DoS or disclose information out of the config files, because of _createUserdataConf in install/lib/class.FroxlorInstall.php.

CVE-2020-10235 froxlor vulnerability CVSS: 6.5 09 Mar 2020, 16:15 UTC

An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in install/lib/class.FroxlorInstall.php.

CVE-2018-1000527 froxlor vulnerability CVSS: 6.5 26 Jun 2018, 16:29 UTC

Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution. This attack appear to be exploitable via Passing malicious PHP objection in $_POST['ssl_ipandport']. This vulnerability appears to have been fixed in after commit c1e62e6.

CVE-2018-12642 froxlor vulnerability CVSS: 5.0 22 Jun 2018, 12:29 UTC

Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

CVE-2015-5959 froxlor vulnerability CVSS: 5.0 06 Sep 2017, 21:29 UTC

Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.

CVE-2016-5100 froxlor vulnerability CVSS: 5.0 13 Feb 2017, 18:59 UTC

Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.