BloofoxCMS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in BloofoxCMS version 0.5.2.1. This issue resides in the articles text parameter, allowing authenticated attackers to inject malicious scripts. The injected JavaScript payloads are executed, potentially leading to the theft of cookies from authenticated users.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, log in with a valid username and password and navigate to the 'articles' tab. Create a new post and insert a payload, such as an image tag with an 'onerror' event, into the 'text' parameter. After saving the post, the injected script will execute each time the post is viewed, enabling cookie theft from authenticated users.

Added: Jan 23, 2026, 5:30 PM
Updated: Jan 23, 2026, 10:23 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
6.1
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.