Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Boonex

First CVE: Feb 22, 2006Active for: 20 yearsTotal CVEs: 14
34.2
VTI Score
Medium

Boonex develops a focused suite of community and social-networking platform products including Dolphin, Orca, Barracuda, and Ray, deployed in hosted and self-managed environments where user-generated content and administrator control are primary attack surfaces. Its vulnerabilities recur through application-layer input-handling and access-control weakness classes—code injection, cross-site scripting, SQL injection, and cross-site request forgery—that are characteristic of web platforms handling dynamic content, and this class of flaw tends to acquire public exploit code. Defenders should prioritize patching instances of these products that face user input or administrative interfaces, and treat this vendor's advisories as applicable across the product line; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Boonex over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2006
20 years ago
Most Recent CVE
Mar 23, 2021
1,952 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-3167HIGH
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the
Jul 14, 20089.342NOYES
CVE-2008-3166HIGH
PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP
Jul 14, 20089.335NOYES
CVE-2008-5167HIGH
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PH
Nov 19, 20089.333NOYES
CVE-2012-0873MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to ex
Feb 23, 20124.326NOYES
CVE-2013-3638HIGH
SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.
Feb 6, 20208.822NONO
CVE-2021-27969MEDIUM
Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.
Mar 23, 20214.819NONO
CVE-2006-2133HIGH
SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_t
May 1, 20067.519NONO
CVE-2014-4333MEDIUM
Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators f
Jun 19, 20146.818NONO
CVE-2014-3810MEDIUM
SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the
Jun 19, 20146.518NONO
CVE-2011-3728MEDIUM
Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated
Sep 23, 20115.018NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
57%
36%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network2 (14.3%)
Unknown12 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None1 (7.1%)
Unknown12 (85.7%)
Required1 (7.1%)
Privileges Required
Low1 (7.1%)
High1 (7.1%)
None0 (0.0%)
Unknown12 (85.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
28.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Boonex.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Boonex — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Boonex's Products

View all 2 CNAs →

Top CWEs