CVE-2023-34752: Bloofox Bloofoxcms

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

Affected products

  • Bloofox Bloofoxcms: version 0.5.2.1 only

Published 2023-06-14. Last modified 2026-07-09.