Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bloofox

First CVE: Dec 29, 2008Active for: 18 yearsTotal CVEs: 27
50.5
VTI Score
TOP TARGET

Bloofox maintains a content-management system that, despite a narrow product portfolio, carries a notably elevated attack surface due to its web-facing role and the cumulative exposure across its user base. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, making patches urgent when released. The exposure recurs consistently through application-layer weakness classes including SQL injection, path traversal, cross-site scripting, unrestricted file uploads, and cross-site request forgery—a cluster characteristic of web applications with insufficient input validation and access controls. Defenders should treat Bloofox CMS advisories as high-priority and verify patching across deployed instances, as the recurring vulnerability patterns indicate systematic input-handling weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bloofox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2008
17 years ago
Most Recent CVE
May 16, 2026
69 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-34755CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
Jun 14, 20239.843NOYES
CVE-2023-34751CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
Jun 14, 20239.842NOYES
CVE-2023-34752CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
Jun 14, 20239.840NOYES
CVE-2023-34756CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
Jun 14, 20239.837NOYES
CVE-2023-34754CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
Jun 14, 20239.837NOYES
CVE-2023-34753CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.
Jun 14, 20239.837NOYES
CVE-2008-5748HIGH
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) modul
Dec 29, 20088.134NOYES
CVE-2023-27812CRITICAL
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
Apr 13, 20239.131NONO
CVE-2021-44610CRITICAL
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) defaul
Feb 24, 20229.830NONO
CVE-2010-4870HIGH
SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.
Oct 7, 20117.530NOYES
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
37%
19%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (92.6%)
Unknown2 (7.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (88.9%)
High1 (3.7%)
Unknown2 (7.4%)
User Interaction
None20 (74.1%)
Unknown2 (7.4%)
Required5 (18.5%)
Privileges Required
Low7 (25.9%)
High3 (11.1%)
None15 (55.6%)
Unknown2 (7.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
22.2% of CVEs· 97th percentile
ExploitDB
3 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bloofox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bloofox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bloofox's Products

View all 2 CNAs →

Top CWEs