CVE-2020-36978: Froxlor Froxlor Server Management Panel

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules.

Affected products

  • Froxlor Froxlor Froxlor Server Management Panel: version 0.10.16 only

Published 2026-01-27. Last modified 2026-06-17.