pkg:Packagist/froxlor/froxlor
共 50 筆 CVECRITICAL11HIGH15MEDIUM22LOW1
✅ 檢查你的版本
所有已知漏洞
- CRITICAL9.9CVE-2026-41228Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Executionfrom 0, < 2.3.6
- from 0, < 2.1.0-beta1
- CRITICAL9.8CVE-2023-3173Froxlor vulnerable to Improper Restriction of Excessive Authentication Attemptsfrom 0, < 2.0.20
- from 0, < 2.0.13
- from 0, < 0.10.30
- from 0, < 0.9.35
- from 0, < 2.1.9
- CRITICAL9.1CVE-2026-41229Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)from 0, < 2.3.6
- CRITICAL9.1CVE-2026-26279Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injectionfrom 0, < 2.3.4
- from 0, < 2.0.21
- CRITICAL9.1CVE-2023-2034froxlor/froxlor vulnerable to unrestricted upload of file with dangerous typefrom 0, < 2.0.14
- HIGH8.8CVE-2026-41236Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path>= 2.3.6, < 2.3.7
- HIGH8.8CVE-2026-41235Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement>= 2.3.6, < 2.3.7
- HIGH8.8CVE-2026-30932Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones APIfrom 0, < 2.3.5
- from 0, < 2.0.11
- from 0, < 2.0.11
- HIGH8.8CVE-2023-0671froxlor is vulnerable to privilege escalation from customer to root via directory-optionsfrom 0, < 2.0.10
- from 0, < 2.0.8
- from 0, < 0.10.14
- HIGH8.5CVE-2026-41230Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()from 0, < 2.3.6
- HIGH7.5CVE-2026-41231Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cronfrom 0, < 2.3.6
- from 0, < 2.1.2
- from 0, < 2.0.10
- from 0, < 0.9.40
- from 0, < 2.0.20
- from 0, < 0.9.40
- from 0, < 2.0.16
- from 0, < 0.10.38
- from 0, < 0.10.38.2
- from 0, < 0.10.14
- from 0, <= 0.10.22
- MEDIUM5.8CVE-2025-29773Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeoverfrom 0, < 2.2.6
- from 0, < 2.2.6
- from 0, < 2.0.0
- from 0, <= 0.10.15
- MEDIUM5.4CVE-2026-41233Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()from 0, < 2.3.6
- from 0, < 2.1.0
- >= 2.0.0-beta0, < 2.0.0-beta1
- from 0, < 2.0.10
- MEDIUM5.0CVE-2026-41232Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofingfrom 0, < 2.3.6
- from 0, < 2.0.10
- from 0, < 2.0.22
- from 0, < 2.1.0-dev1
- from 0, < 2.0.10
- from 0, < 0.10.39
- >= 2.0.0-beta0, < 2.0.0-beta1
- >= 2.0.0-beta0, < 2.0.0-beta1
- from 0, < 2.0.22
- from 0, < 2.3.7