← Back

Bloofox

bloofox

26 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Bloofoxcms
bloofoxcms

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bloofox
1Bloofoxcms
Jun 17, 2026
Aug 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Apr 13, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Apr 13, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Apr 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters i...Show more
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.Show less
1Bloofox
1Bloofoxcms
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 16, 2021
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 16, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 4, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 4, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.