CVE-2016-5100: Froxlor

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.

Affected products

  • Froxlor Froxlor: up to and including 0.9.34.2

Published 2017-02-13. Last modified 2026-06-17.