Vulnerabilities > Bloofox > Bloofoxcms > 0.5.2.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-11 | CVE-2020-36082 | Unrestricted Upload of File with Dangerous Type vulnerability in Bloofox Bloofoxcms 0.5.2.1 File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module. | 9.8 |
2023-06-14 | CVE-2023-34750 | SQL Injection vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit. | 9.8 |
2023-06-14 | CVE-2023-34751 | SQL Injection vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | 9.8 |
2023-06-14 | CVE-2023-34752 | SQL Injection vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. | 9.8 |
2023-06-14 | CVE-2023-34753 | SQL Injection vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | 9.8 |
2023-06-14 | CVE-2023-34754 | SQL Injection vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit. | 9.8 |
2023-06-14 | CVE-2023-34755 | SQL Injection vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | 9.8 |
2023-06-14 | CVE-2023-34756 | SQL Injection vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | 9.8 |
2023-01-26 | CVE-2023-23151 | Unspecified vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php. | 6.5 |
2022-04-26 | CVE-2022-28528 | Unrestricted Upload of File with Dangerous Type vulnerability in Bloofox Bloofoxcms 0.5.2.1 bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | 8.8 |