VYPR

Bloofoxcms

by Bloofoxcms

Source repositories

CVEs (32)

  • CVE-2020-36082CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

  • CVE-2023-34756CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

  • CVE-2023-34755CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

  • CVE-2023-34754CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.03

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

  • CVE-2023-34753CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

  • CVE-2023-34752CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

  • CVE-2023-34751CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

  • CVE-2023-34750CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

  • CVE-2021-44610CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.

  • CVE-2020-35760CriJun 16, 2021
    risk 0.64cvss 9.8epss 0.02

    bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).

  • CVE-2023-27812CriApr 13, 2023
    risk 0.59cvss 9.1epss 0.01

    bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

  • CVE-2023-29597HigApr 13, 2023
    risk 0.57cvss 8.8epss 0.01

    bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

  • CVE-2022-28528HigApr 26, 2022
    risk 0.57cvss 8.8epss 0.01

    bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

  • CVE-2020-36141HigJun 4, 2021
    risk 0.57cvss 8.8epss 0.01

    BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.

  • CVE-2008-5748HigDec 29, 2008
    risk 0.56cvss 8.1epss 0.10

    Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.

  • CVE-2021-47906MedJan 23, 2026
    risk 0.42cvss 6.4epss 0.00

    BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal…

  • CVE-2023-23151MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.

  • CVE-2020-35759MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.01

    bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

  • CVE-2020-36142MedJun 4, 2021
    risk 0.42cvss 6.5epss 0.01

    BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.

  • CVE-2020-36140MedJun 4, 2021
    risk 0.42cvss 6.5epss 0.01

    BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).

Page 1 of 2