CVE-2026-100719: Froxlor
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, enabling offline cracking attempts and exposure of reused credentials.
Affected products
- Froxlor Froxlor: before 2.3.12 (fixed in 2.3.12)
Published 2026-09-26. Last modified 2026-09-26.