Boonex develops a focused suite of community and social-networking platform products including Dolphin, Orca, Barracuda, and Ray, deployed in hosted and self-managed environments where user-generated content and administrator control are primary attack surfaces. Its vulnerabilities recur through application-layer input-handling and access-control weakness classes—code injection, cross-site scripting, SQL injection, and cross-site request forgery—that are characteristic of web platforms handling dynamic content, and this class of flaw tends to acquire public exploit code. Defenders should prioritize patching instances of these products that face user input or administrative interfaces, and treat this vendor's advisories as applicable across the product line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boonex over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3167HIGH Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the | Jul 14, 2008 | 9.3 | 42 | NO | YES |
CVE-2008-3166HIGH PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP | Jul 14, 2008 | 9.3 | 35 | NO | YES |
CVE-2008-5167HIGH PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PH | Nov 19, 2008 | 9.3 | 33 | NO | YES |
CVE-2012-0873MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to ex | Feb 23, 2012 | 4.3 | 26 | NO | YES |
CVE-2013-3638HIGH SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'. | Feb 6, 2020 | 8.8 | 22 | NO | NO |
CVE-2021-27969MEDIUM Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter. | Mar 23, 2021 | 4.8 | 19 | NO | NO |
CVE-2006-2133HIGH SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_t | May 1, 2006 | 7.5 | 19 | NO | NO |
CVE-2014-4333MEDIUM Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators f | Jun 19, 2014 | 6.8 | 18 | NO | NO |
CVE-2014-3810MEDIUM SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the | Jun 19, 2014 | 6.5 | 18 | NO | NO |
CVE-2011-3728MEDIUM Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated | Sep 23, 2011 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boonex.
Media articles that mention a CVE ID that affects a product developed by Boonex — matched by CVE ID, not by vendor name.