VYPR

Bloofoxcms

by Bloofoxcms

Source repositories

CVEs (32)

  • CVE-2021-44608MedFeb 24, 2022
    risk 0.35cvss 5.4epss 0.00

    Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.

  • CVE-2020-35761MedJun 16, 2021
    risk 0.35cvss 5.4epss 0.01

    bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.

  • CVE-2020-36139MedJun 4, 2021
    risk 0.35cvss 5.4epss 0.01

    BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.

  • CVE-2020-37241MedMay 16, 2026
    risk 0.34cvss 5.3epss 0.00

    bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new…

  • CVE-2020-35709MedDec 25, 2020
    risk 0.32cvss 4.9epss 0.01

    bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

  • CVE-2020-35762LowJun 16, 2021
    risk 0.18cvss 2.7epss 0.01

    bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.

  • CVE-2010-4870Oct 7, 2011
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

  • CVE-2009-4522Dec 31, 2009
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2008-0427Jan 23, 2008
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2008-0428Jan 23, 2008
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php.

  • CVE-2007-2310Apr 26, 2007
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.

  • CVE-2007-2311Apr 26, 2007
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the content_php parameter. NOTE: this issue has been disputed by a reliable third party, stating that content_php is initialized…

Page 2 of 2