彙總 bloofox 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
歷史漏洞主要涉及 SQL 注入與跨站腳本 等問題,部分漏洞可能導致 資料外洩,並影響 軟體部署與生產負載 相關場景。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2020-37241 | bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts with arbitrary credentials without requiring explicit user consent. | [email protected] | 6.9 | 0.15% | 2026-05-16 | 2026-06-16 |
| CVE-2021-47906 | BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies. | [email protected] | 5.1 | 0.20% | 2026-01-23 | 2026-06-17 |
| CVE-2020-36082 | File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module. | [email protected] | 9.8 | 0.94% | 2023-08-11 | 2026-06-16 |
| CVE-2023-34756 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | [email protected] | 9.8 | 4.23% | 2023-06-14 | 2026-06-17 |
| CVE-2023-34755 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | [email protected] | 9.8 | 4.23% | 2023-06-14 | 2026-06-17 |
| CVE-2023-34754 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit. | [email protected] | 9.8 | 3.45% | 2023-06-14 | 2026-06-17 |
| CVE-2023-34753 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | [email protected] | 9.8 | 4.23% | 2023-06-14 | 2026-06-17 |
| CVE-2023-34752 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. | [email protected] | 9.8 | 4.38% | 2023-06-14 | 2026-07-08 |
| CVE-2023-34751 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | [email protected] | 9.8 | 4.23% | 2023-06-14 | 2026-06-17 |
| CVE-2023-34750 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit. | [email protected] | 9.8 | 1.01% | 2023-06-14 | 2026-06-17 |
| CVE-2023-29597 | bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1. | [email protected] | 8.8 | 0.72% | 2023-04-13 | 2026-06-17 |
| CVE-2023-27812 | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | [email protected] | 9.1 | 1.22% | 2023-04-13 | 2026-07-08 |
| CVE-2023-23151 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php. | [email protected] | 6.5 | 1.04% | 2023-01-26 | 2026-06-17 |
| CVE-2022-28528 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | [email protected] | 8.8 | 1.18% | 2022-04-26 | 2026-06-17 |
| CVE-2021-44610 | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php. | [email protected] | 9.8 | 1.35% | 2022-02-24 | 2026-06-17 |
| CVE-2021-44608 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php. | [email protected] | 5.4 | 0.48% | 2022-02-24 | 2026-06-17 |
| CVE-2020-35762 | bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files. | [email protected] | 2.7 | 0.97% | 2021-06-16 | 2026-06-16 |
| CVE-2020-35761 | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. | [email protected] | 5.4 | 0.83% | 2021-06-16 | 2026-06-16 |
| CVE-2020-35760 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files). | [email protected] | 9.8 | 1.89% | 2021-06-16 | 2026-06-16 |
| CVE-2020-35759 | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). | [email protected] | 6.5 | 0.84% | 2021-06-16 | 2026-06-16 |