bloofox CVE Vulnerabilities & Metrics

Focus on bloofox vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About bloofox Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with bloofox. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total bloofox CVEs: 23
Earliest CVE date: 29 Dec 2008, 15:24 UTC
Latest CVE date: 11 Aug 2023, 14:15 UTC

Latest CVE reference: CVE-2020-36082

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical bloofox CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.89

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 14
4.0-6.9 9
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS bloofox CVEs

These are the five CVEs with the highest CVSS scores for bloofox, sorted by severity first and recency.

All CVEs for bloofox

CVE-2020-36082 bloofox vulnerability CVSS: 0 11 Aug 2023, 14:15 UTC

File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

CVE-2023-34756 bloofox vulnerability CVSS: 0 14 Jun 2023, 14:15 UTC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

CVE-2023-34755 bloofox vulnerability CVSS: 0 14 Jun 2023, 14:15 UTC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

CVE-2023-34754 bloofox vulnerability CVSS: 0 14 Jun 2023, 14:15 UTC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

CVE-2023-34753 bloofox vulnerability CVSS: 0 14 Jun 2023, 14:15 UTC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

CVE-2023-34752 bloofox vulnerability CVSS: 0 14 Jun 2023, 14:15 UTC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVE-2023-34751 bloofox vulnerability CVSS: 0 14 Jun 2023, 14:15 UTC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

CVE-2023-34750 bloofox vulnerability CVSS: 0 14 Jun 2023, 14:15 UTC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

CVE-2023-29597 bloofox vulnerability CVSS: 0 13 Apr 2023, 14:15 UTC

bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

CVE-2023-27812 bloofox vulnerability CVSS: 0 13 Apr 2023, 14:15 UTC

bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.

CVE-2023-23151 bloofox vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.

CVE-2022-28528 bloofox vulnerability CVSS: 6.5 26 Apr 2022, 21:15 UTC

bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

CVE-2021-44610 bloofox vulnerability CVSS: 7.5 24 Feb 2022, 15:15 UTC

Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.

CVE-2021-44608 bloofox vulnerability CVSS: 3.5 24 Feb 2022, 15:15 UTC

Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.

CVE-2020-35762 bloofox vulnerability CVSS: 4.0 16 Jun 2021, 16:15 UTC

bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.

CVE-2020-35761 bloofox vulnerability CVSS: 3.5 16 Jun 2021, 16:15 UTC

bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.

CVE-2020-35760 bloofox vulnerability CVSS: 7.5 16 Jun 2021, 16:15 UTC

bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).

CVE-2020-35759 bloofox vulnerability CVSS: 4.3 16 Jun 2021, 16:15 UTC

bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

CVE-2020-36142 bloofox vulnerability CVSS: 4.0 04 Jun 2021, 16:15 UTC

BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.

CVE-2020-36141 bloofox vulnerability CVSS: 6.5 04 Jun 2021, 16:15 UTC

BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.

CVE-2020-36140 bloofox vulnerability CVSS: 4.3 04 Jun 2021, 16:15 UTC

BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).

CVE-2020-36139 bloofox vulnerability CVSS: 3.5 04 Jun 2021, 16:15 UTC

BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.

CVE-2020-35709 bloofox vulnerability CVSS: 4.0 25 Dec 2020, 19:15 UTC

bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.

CVE-2010-4870 bloofox vulnerability CVSS: 7.5 07 Oct 2011, 10:55 UTC

SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

CVE-2009-4522 bloofox vulnerability CVSS: 4.3 31 Dec 2009, 19:30 UTC

Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2008-5748 bloofox vulnerability CVSS: 4.3 29 Dec 2008, 15:24 UTC

Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.