These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-90937 is a critical vulnerability in froxlor versions before 2.2.5, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives via subdomain redirect URLs. This can lead to web server configuration corruption, denial of service, or hijacking of HTTP responses across hosted domains. The vulnerability is caused by a lack of validation of newline characters in subd [truncated]
CVE-2026-90936 is a medium-severity vulnerability in Froxlor versions prior to 2.3.7. The issue arises from improper scoping of sender alias lookups in customer_email.php, allowing authenticated attackers to enumerate global sender alias IDs and read other customers' allowed sender values. This vulnerability impacts Froxlor installations, particularly those using versions prior to 2.3.7, and requires veri [truncated]
CVE-2026-90935 is a vulnerability in Froxlor versions before 2.3.7, where the mysql_server parameter is not validated against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. This allows attackers to create MySQL databases and users on forbidden servers, bypassing per-customer access controls. The vulnerability impacts Froxlor installations, specifically affecting access controls [truncated]
CVE-2024-58383 is a high-severity vulnerability in Froxlor versions before 2.2.0, where the /etc/pure-ftpd/db/mysql.conf file is generated with insecure permissions, allowing unprivileged local users to obtain Froxlor database credentials. This can lead to potential privilege escalation and requires immediate attention from system administrators and security teams. The vulnerability affects systems using [truncated]
CVE-2026-90767 is a vulnerability in Froxlor versions before 2.3.12 that allows customers to inject arbitrary lines into authorized_keys files via the SshKeys::add() endpoint. This enables attackers to gain persistent unauthorized access. The vulnerability affects Froxlor installations, and defenders should assess exposure and apply remediation. The issue arises from improper validation of multi-line SSH [truncated]
The Froxlor server administration software has a critical vulnerability (CVE-2026-62988) that exposes sensitive information through its API commands for customers, admins, and FTP users. An authenticated API caller can obtain full database rows, including password hashes and Base32-encoded TOTP seeds, which can be used to crack passwords offline and generate valid second-factor codes. This issue is fixed [truncated]
CVE-2026-55593 is a vulnerability in Froxlor, an open-source server administration software. The vulnerability allows an unauthenticated attacker to induce an authenticated administrator's browser to submit a forged request that adds an attacker-controlled address to an API key's allowed_from list or removes its expiration, weakening the key's security restrictions. This issue is fixed in version 2.3.8.
CVE-2026-54543 is a vulnerability in Froxlor, an open-source server administration software. The DomainZones.add API command does not properly validate user-controlled record and type values, allowing an authenticated customer with DNS-zone permissions to inject crafted values and create additional resource-record lines in the BIND zone file. This could lead to modification of DNS data and potential DNS a [truncated]
CVE-2026-54348 debrief based on the supplied source corpus. Froxlor server administration software has a vulnerability in the Admins.add and Admins.update endpoints, allowing an authenticated administrator to store a UNION-based payload and retrieve arbitrary database data. This issue is fixed in version 2.3.8. Administrators and users of affected versions should assess exposure and verify patch deploymen [truncated]
An authenticated customer with DNS editor access can store JavaScript-bearing content in a TXT record. When an administrator views the affected domain's DNS configuration, the payload executes automatically in the administrator's browser session, which can expose session data or perform privileged panel actions. This stored XSS vulnerability affects Froxlor's DNS TXT record handling, allowing an attacker [truncated]
CVE-2026-52793 is a high-severity vulnerability in Froxlor, an open-source server administration software. The issue allows an attacker with a valid API key and secret to access and modify sensitive data without providing a second factor of authentication, even if two-factor authentication is enabled for the account. This can lead to exposure or modification of customer data, domains, email and FTP accoun [truncated]
A vulnerability was discovered in Froxlor, an open-source server administration software. The issue, tracked as CVE-2026-41237, affects version 2.3.6 and earlier. The vulnerability arises from the LOC record regex using `s+`, which matches newlines, allowing embedded newlines to pass. Additionally, TLSA `matching=0` has no upper bound on hex data length, and all validators return raw input without zone-fi [truncated]
CVE-2026-41236 is a HIGH-severity vulnerability in Froxlor server administration software. Version 2.3.6 of Froxlor contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` under a customer-controlled home directory without verifying that the target path is not a symbolic link. An att [truncated]
Froxlor server administration software version 2.3.6 has a vulnerability allowing authenticated customers with shell delegation enabled to submit an arbitrary shell, potentially leading to real host shell access. The issue is fixed in version 2.3.7.
CVE-2026-41234 is a HIGH severity vulnerability in Froxlor server administration software. An authenticated customer with DNS editing enabled can inject newlines into TXT record values via the `DomainZones.add` API endpoint. This allows for injection of arbitrary BIND directives and DNS records into the zone file written to disk by the DNS rebuild cron. This is an incomplete fix for CVE-2026-30932. Versio [truncated]
CVE-2016-5100 is a critical authentication weakness in Froxlor versions before 0.9.35. The issue stems from using PHP rand for random number generation in password reset token creation, which can make tokens easier to predict. Because password reset flows are security-sensitive, this can expose accounts to unauthorized takeover if an attacker can guess a valid token.