Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Lipeiyi

#21084of 56,330
13.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-41441
6.9
2026-05-16
Bloofox · Bloofoxcms · CVE-2020-37241
**Name of the Vulnerable Software and Affected Versions** bloofoxCMS version 0.5.2.1 **Description** A cross-site request forgery issue allows attackers to perform administrative actions by tricking authenticated users into visiting malicious pages. Attackers can use hidden forms targeting the admin user creation endpoint to create new administrative accounts with arbitrary credentials without the user's consent. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-4519
6.4
2026-01-23
Unknown · Bloofoxcms · CVE-2021-47906
**Name of the Vulnerable Software and Affected Versions** BloofoxCMS version 0.5.2.1 **Description** BloofoxCMS contains a stored cross-site scripting issue. Authenticated attackers can inject malicious scripts through the `text` parameter in the articles section. This allows for the execution of scripts and potential theft of authenticated users' cookies. **Recommendations** Apply updates to address the issue in the articles section. As a temporary workaround, sanitize all input to the `text` parameter to prevent script injection.