BloofoxCVEs & Vulnerabilities

26 CVEs affecting Bloofox products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

bloofoxcms 26
CVE-2020-36082CRITICAL

File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

11 Aug 2023
9.8
CVSS
CVE-2023-34756CRITICAL

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

14 Jun 2023
9.8
CVSS
CVE-2023-34755CRITICAL

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

14 Jun 2023
9.8
CVSS
CVE-2023-34754CRITICAL

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

14 Jun 2023
9.8
CVSS
CVE-2023-34753CRITICAL

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

14 Jun 2023
9.8
CVSS
CVE-2023-34752CRITICAL

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

14 Jun 2023
9.8
CVSS
CVE-2023-34751CRITICAL

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

14 Jun 2023
9.8
CVSS
CVE-2023-34750CRITICAL

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

14 Jun 2023
9.8
CVSS
CVE-2023-29597HIGH

bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

13 Apr 2023
8.8
CVSS
CVE-2023-27812CRITICAL

bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

13 Apr 2023
9.1
CVSS
CVE-2023-23151MEDIUM

bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.

27 Jan 2023
6.5
CVSS
CVE-2022-28528HIGH

bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

27 Apr 2022
8.8
CVSS
CVE-2021-44610CRITICAL

Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.

24 Feb 2022
9.8
CVSS
CVE-2021-44608MEDIUM

Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.

24 Feb 2022
5.4
CVSS
CVE-2020-35762LOW

bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.

16 Jun 2021
2.7
CVSS
CVE-2020-35761MEDIUM

bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.

16 Jun 2021
5.4
CVSS
CVE-2020-35760CRITICAL

bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).

16 Jun 2021
9.8
CVSS
CVE-2020-35759MEDIUM

bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

16 Jun 2021
6.5
CVSS
CVE-2020-36142MEDIUM

BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.

4 Jun 2021
6.5
CVSS
CVE-2020-36141HIGH

BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.

4 Jun 2021
8.8
CVSS
CVE-2020-36140MEDIUM

BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).

4 Jun 2021
6.5
CVSS
CVE-2020-36139MEDIUM

BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.

4 Jun 2021
5.4
CVSS
CVE-2020-35709MEDIUM

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

25 Dec 2020
4.9
CVSS
CVE-2010-4870HIGHpoc

SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

7 Oct 2011
7.5
CVSS
CVE-2009-4522MEDIUMpoc

Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php. NOTE: some of these details are obtained from third party information.

31 Dec 2009
4.3
CVSS
CVE-2008-5748HIGHpoc

Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.

29 Dec 2008
8.1
CVSS
← PrevPage 1 / 1Next →
Bloofox CVEs & Vulnerabilities — 26 Tracked