Skip to main content

Vendor/product archive

boltcms / bolt CVEs

Beta · best-effort

19 CVEs tagged to boltcms / bolt1 Critical, 6 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2025-34086

Published Jul 3, 2025

Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7300

Published Jul 31, 2024

A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7299

Published Jul 31, 2024

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects some unknown processing of the file /preview/page…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31321

Published Aug 1, 2022

The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) vi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27367

Published Feb 17, 2021

Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28925

Published Dec 30, 2020

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4041

Published Jun 8, 2020

In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javascript code in the file name when creating/uploadin…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4040

Published Jun 8, 2020

Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editor…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9553

Published Dec 31, 2019

Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20058

Published Dec 29, 2019

Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15485

Published Aug 23, 2019

Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15484

Published Aug 23, 2019

Bolt before 3.6.10 has XSS via an image's alt or title field.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15483

Published Aug 23, 2019

Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10874

Published Apr 5, 2019

Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to incl…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9185

Published Mar 7, 2019

Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16754

Published Nov 10, 2017

Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11128

Published Jul 17, 2017

Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11127

Published Jul 17, 2017

Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7309

Published Sep 22, 2015

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1