Products: 5
    Vulnerabilities: 14
    Known Exploited: 0
    3
    Critical Level Threats
    2
    High Level Threats
    8
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-27969

    Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.

    Last Modified: Nov 21, 2024
    Published: Mar 23, 2021

    CVE-2013-3638

    SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.

    Last Modified: Nov 21, 2024
    Published: Feb 06, 2020

    CVE-2014-4333

    Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810.

    Last Modified: Apr 12, 2025
    Published: Jun 19, 2014

    CVE-2014-3810

    SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-4333.

    Last Modified: Apr 12, 2025
    Published: Jun 19, 2014

    CVE-2012-0873

    Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode parameters to viewFriends.php.

    Last Modified: Apr 11, 2025
    Published: Feb 23, 2012
    Items Per Page
    Boonex Vulnerabilities & Security CVEs | CVE-DB