CVE-2020-36141: Bloofox Bloofoxcms

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.

Affected products

  • Bloofox Bloofoxcms: version 0.5.2.1 only

Published 2021-06-04. Last modified 2026-06-17.