Home/Product/boltcms bolt
Product

boltcms bolt

22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-34086
<= 3.7.0
Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote
8.8HIGH
CVE-2024-7300
all versions
A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/edit
3.5LOW
CVE-2024-7299
all versions
UNSUPPORTED WHEN ASSIGNED A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects
3.5LOW
CVE-2022-36532
<= 5.1.12
Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to
8.8HIGH
CVE-2022-31321
<= 5.7
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory
9.1CRITICAL
CVE-2021-40219
<= 4.2.0
Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to i
8.8HIGH
CVE-2021-27367
< 4.1.13
Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory T
7.5HIGH
CVE-2020-28925
< 3.7.2
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How t
5.3MEDIUM
CVE-2020-4041
< 3.7.1
In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javasc
7.4HIGH
CVE-2020-4040
< 3.7.1
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by
8.6HIGH
CVE-2019-9553
all versions
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-1
6.1MEDIUM
CVE-2019-20058
all versions
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. N
6.1MEDIUM
CVE-2019-15485
< 3.6.10
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
6.1MEDIUM
CVE-2019-15484
< 3.6.10
Bolt before 3.6.10 has XSS via an image's alt or title field.
6.1MEDIUM
CVE-2019-15483
< 3.6.10
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
6.1MEDIUM
CVE-2019-10874
all versions
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbi
8.8HIGH
CVE-2019-9185
< 3.6.5
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP co
8.8HIGH
CVE-2018-19933
< 3.6.2
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
6.1MEDIUM
CVE-2017-16754
<= 3.3.5
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provide
5.3MEDIUM
CVE-2017-11128
all versions
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
5.4MEDIUM
CVE-2017-11127
all versions
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
5.4MEDIUM
CVE-2015-7309
<= 2.2.0
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated use
threatengine.sh