CVE-2021-47906 PUBLISHED

BloofoxCMS 0.5.2.1 - 'text' Stored Cross Site Scripting

Assigner: VulnCheck
Reserved: 18.01.2026 Published: 23.01.2026 Updated: 23.01.2026

BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor BloofoxCMS
Product BloofoxCMS
Versions
  • Version 0.5.1.0 - 0.5.2.1 is affected

Credits

  • LiPeiYi finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE