Vulnerabilities > Bloofox > Bloofoxcms > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-23151 Unspecified vulnerability in Bloofox Bloofoxcms 0.5.2.1
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.
network
low complexity
bloofox
6.5
2022-04-26 CVE-2022-28528 Unrestricted Upload of File with Dangerous Type vulnerability in Bloofox Bloofoxcms 0.5.2.1
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
network
low complexity
bloofox CWE-434
6.5
2021-06-16 CVE-2020-35759 Cross-Site Request Forgery (CSRF) vulnerability in Bloofox Bloofoxcms 0.5.2.1
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
network
bloofox CWE-352
4.3
2021-06-16 CVE-2020-35762 Path Traversal vulnerability in Bloofox Bloofoxcms 0.5.2.1
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
network
low complexity
bloofox CWE-22
4.0
2021-06-04 CVE-2020-36139 Cross-site Scripting vulnerability in Bloofox Bloofoxcms 0.5.2.1
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
network
low complexity
bloofox CWE-79
5.4
2021-06-04 CVE-2020-36140 Cross-Site Request Forgery (CSRF) vulnerability in Bloofox Bloofoxcms 0.5.2.1
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
network
low complexity
bloofox CWE-352
6.5
2021-06-04 CVE-2020-36142 Path Traversal vulnerability in Bloofox Bloofoxcms 0.5.2.1
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
network
low complexity
bloofox CWE-22
6.5
2020-12-25 CVE-2020-35709 Path Traversal vulnerability in Bloofox Bloofoxcms 0.5.2.1
bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.
network
low complexity
bloofox CWE-22
4.0
2009-12-31 CVE-2009-4522 Cross-Site Scripting vulnerability in Bloofox Bloofoxcms 0.3.5
Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php.
network
bloofox CWE-79
4.3