Known Vulnerabilities for products from Bloofox
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Bloofox".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-34756 json | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settin... | 9.8 - CRITICAL | 2023-06-14 | 2023-06-17 |
| CVE-2023-34755 json | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=use... | 9.8 - CRITICAL | 2023-06-14 | 2023-06-17 |
| CVE-2023-34754 json | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settin... | 9.8 - CRITICAL | 2023-06-14 | 2023-06-17 |
| CVE-2023-34753 json | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settin... | 9.8 - CRITICAL | 2023-06-14 | 2023-06-17 |
| CVE-2023-34752 json | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settin... | 9.8 - CRITICAL | 2023-06-14 | 2023-06-17 |
| CVE-2023-34751 json | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&p... | 9.8 - CRITICAL | 2023-06-14 | 2023-06-17 |
| CVE-2023-34750 json | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settin... | 9.8 - CRITICAL | 2023-06-14 | 2023-06-17 |
| CVE-2023-29597 json | bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&a... | 8.8 - HIGH | 2023-04-13 | 2023-12-22 |
| CVE-2023-27812 json | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | 9.1 - CRITICAL | 2023-04-13 | 2023-12-22 |
| CVE-2023-23151 json | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content... | 6.5 - MEDIUM | 2023-01-26 | 2023-02-02 |
| CVE-2022-28528 json | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=m... | 8.8 - HIGH | 2022-04-26 | 2022-05-05 |
| CVE-2021-44610 json | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mo... | 9.8 - CRITICAL | 2022-02-24 | 2022-03-03 |
| CVE-2021-44608 json | Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) t... | 5.4 - MEDIUM | 2022-02-24 | 2022-03-03 |
| CVE-2020-36142 json | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. | 6.5 - MEDIUM | 2021-06-04 | 2021-06-09 |
| CVE-2020-36141 json | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' wi... | 8.8 - HIGH | 2021-06-04 | 2021-06-09 |
| CVE-2020-36140 json | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=... | 6.5 - MEDIUM | 2021-06-04 | 2021-06-09 |
| CVE-2020-36139 json | BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' ... | 5.4 - MEDIUM | 2021-06-04 | 2021-06-08 |
| CVE-2020-36082 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2023-08-11 | 2023-08-16 |
| CVE-2020-35762 json | bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files. | 2.7 - LOW | 2021-06-16 | 2021-06-17 |
| CVE-2020-35761 json | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. | 5.4 - MEDIUM | 2021-06-16 | 2021-06-17 |