Bloofox maintains a content-management system that, despite a narrow product portfolio, carries a notably elevated attack surface due to its web-facing role and the cumulative exposure across its user base. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, making patches urgent when released. The exposure recurs consistently through application-layer weakness classes including SQL injection, path traversal, cross-site scripting, unrestricted file uploads, and cross-site request forgery—a cluster characteristic of web applications with insufficient input validation and access controls. Defenders should treat Bloofox CMS advisories as high-priority and verify patching across deployed instances, as the recurring vulnerability patterns indicate systematic input-handling weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bloofox over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34755CRITICAL bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | Jun 14, 2023 | 9.8 | 43 | NO | YES |
CVE-2023-34751CRITICAL bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | Jun 14, 2023 | 9.8 | 42 | NO | YES |
CVE-2023-34752CRITICAL bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. | Jun 14, 2023 | 9.8 | 40 | NO | YES |
CVE-2023-34756CRITICAL bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | Jun 14, 2023 | 9.8 | 37 | NO | YES |
CVE-2023-34754CRITICAL bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit. | Jun 14, 2023 | 9.8 | 37 | NO | YES |
CVE-2023-34753CRITICAL bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | Jun 14, 2023 | 9.8 | 37 | NO | YES |
CVE-2008-5748HIGH Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) modul | Dec 29, 2008 | 8.1 | 34 | NO | YES |
CVE-2023-27812CRITICAL bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | Apr 13, 2023 | 9.1 | 31 | NO | NO |
CVE-2021-44610CRITICAL Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) defaul | Feb 24, 2022 | 9.8 | 30 | NO | NO |
CVE-2010-4870HIGH SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter. | Oct 7, 2011 | 7.5 | 30 | NO | YES |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bloofox.
Media articles that mention a CVE ID that affects a product developed by Bloofox — matched by CVE ID, not by vendor name.