Bloofoxcms
by Bloofoxcms
Source repositories
CVEs (32)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36082 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2023 | File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module. | ||
| CVE-2023-34756 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | ||
| CVE-2023-34755 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | ||
| CVE-2023-34754 | Cri | 0.64 | 9.8 | 0.03 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit. | ||
| CVE-2023-34753 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | ||
| CVE-2023-34752 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. | ||
| CVE-2023-34751 | Cri | 0.64 | 9.8 | 0.04 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | ||
| CVE-2023-34750 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2023 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit. | ||
| CVE-2021-44610 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php. | ||
| CVE-2020-35760 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files). | ||
| CVE-2023-27812 | Cri | 0.59 | 9.1 | 0.01 | Apr 13, 2023 | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | ||
| CVE-2023-29597 | Hig | 0.57 | 8.8 | 0.01 | Apr 13, 2023 | bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1. | ||
| CVE-2022-28528 | Hig | 0.57 | 8.8 | 0.01 | Apr 26, 2022 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | ||
| CVE-2020-36141 | Hig | 0.57 | 8.8 | 0.01 | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header. | ||
| CVE-2008-5748 | Hig | 0.56 | 8.1 | 0.10 | Dec 29, 2008 | Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters. | ||
| CVE-2021-47906 | Med | 0.42 | 6.4 | 0.00 | Jan 23, 2026 | BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal… | ||
| CVE-2023-23151 | Med | 0.42 | 6.5 | 0.01 | Jan 26, 2023 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php. | ||
| CVE-2020-35759 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2021 | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). | ||
| CVE-2020-36142 | Med | 0.42 | 6.5 | 0.01 | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. | ||
| CVE-2020-36140 | Med | 0.42 | 6.5 | 0.01 | Jun 4, 2021 | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely). |
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
- risk 0.64cvss 9.8epss 0.03
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
- risk 0.64cvss 9.8epss 0.04
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
- risk 0.64cvss 9.8epss 0.01
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.
- risk 0.64cvss 9.8epss 0.01
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.
- risk 0.64cvss 9.8epss 0.02
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
- risk 0.59cvss 9.1epss 0.01
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
- risk 0.57cvss 8.8epss 0.01
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.
- risk 0.57cvss 8.8epss 0.01
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
- risk 0.57cvss 8.8epss 0.01
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
- risk 0.56cvss 8.1epss 0.10
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.
- risk 0.42cvss 6.4epss 0.00
BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal…
- risk 0.42cvss 6.5epss 0.01
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.
- risk 0.42cvss 6.5epss 0.01
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
- risk 0.42cvss 6.5epss 0.01
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
- risk 0.42cvss 6.5epss 0.01
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
Page 1 of 2