boltcms records
19 published records for vendor boltcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 10.5%
- Pre-auth RCE
- 1
- With a fix record
- 52.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2015-7309Weaponized | The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execboltcms · bolt · CWE-74 | Medium6.5 | — | 38.6% | Sep 22, 2015 |
36Monitor | CVE-2019-10874Proof of concept | Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary codeboltcms · bolt · CWE-352 | High8.8 | — | 4.5% | Apr 5, 2019 |
36Monitor | CVE-2019-9185No exploit | Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaboltcms · bolt · CWE-434 | High8.8 | — | 2.7% | Mar 7, 2019 |
36Monitor | CVE-2022-31321No exploit | The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeratioboltcms · bolt · CWE-20 | Critical9.1 | — | 0.9% | Aug 1, 2022 |
31Monitor | CVE-2025-34086Weaponized | Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Renameboltcms · bolt · CWE-94 | High7.5 | — | 3.6% | Jul 3, 2025 |
31Monitor | CVE-2021-27367No exploit | Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.boltcms · bolt · CWE-22 | High7.5 | — | 1.7% | Feb 17, 2021 |
25Monitor | CVE-2020-4041No exploit | The filename of uploaded files vulnerable to stored XSS in Bolt CMSboltcms · bolt · CWE-79 | Medium6.1 | — | 2.0% | Jun 8, 2020 |
25Monitor | CVE-2019-9553Proof of concept | Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.boltcms · bolt · CWE-79 | Medium6.1 | — | 1.8% | Dec 31, 2019 |
24Monitor | CVE-2019-15485No exploit | Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.boltcms · bolt · CWE-79 | Medium6.1 | — | 0.9% | Aug 23, 2019 |
24Monitor | CVE-2019-15484No exploit | Bolt before 3.6.10 has XSS via an image's alt or title field.boltcms · bolt · CWE-79 | Medium6.1 | — | 0.9% | Aug 23, 2019 |
24Monitor | CVE-2019-15483No exploit | Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.boltcms · bolt · CWE-79 | Medium6.1 | — | 0.9% | Aug 23, 2019 |
24Monitor | CVE-2019-20058No exploit | Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page.boltcms · bolt · CWE-79 | Medium6.1 | — | 0.7% | Dec 29, 2019 |
22Monitor | CVE-2017-16754No exploit | Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventLisboltcms · bolt · CWE-732 | Medium5.3 | — | 1.8% | Nov 9, 2017 |
21Monitor | CVE-2020-28925No exploit | Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Yboltcms · bolt | Medium5.3 | — | 1.1% | Dec 30, 2020 |
21Monitor | CVE-2017-11127No exploit | Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.boltcms · bolt · CWE-79 | Medium5.4 | — | 0.6% | Jul 17, 2017 |
21Monitor | CVE-2017-11128No exploit | Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.boltcms · bolt · CWE-79 | Medium5.4 | — | 0.6% | Jul 17, 2017 |
21Monitor | CVE-2024-7300No exploit | Bolt CMS Showcase Creation showcases cross site scriptingboltcms · bolt · CWE-79 | Medium5.3 | — | 0.4% | Jul 31, 2024 |
21Monitor | CVE-2024-7299No exploit | Bolt CMS Entry Preview page cross site scriptingboltcms · bolt · CWE-79 | Medium5.3 | — | 0.4% | Jul 31, 2024 |
18Monitor | CVE-2020-4040Proof of concept | CSRF issue on preview pages in Bolt CMSboltcms · bolt · CWE-352 | Medium4.3 | — | 1.8% | Jun 8, 2020 |
- CVE-2015-730938Monitor
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to exec
MediumCVSS 6.5WeaponizedEPSS 39%boltcms · boltSep 22, 2015
- CVE-2019-1087436Monitor
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code
HighCVSS 8.8Proof of conceptEPSS 5%boltcms · boltApr 5, 2019
- CVE-2019-918536Monitor
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by rena
HighCVSS 8.8No exploitEPSS 3%boltcms · boltMar 7, 2019
- CVE-2022-3132136Monitor
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeratio
CriticalCVSS 9.1No exploitEPSS 1%boltcms · boltAug 1, 2022
- CVE-2025-3408631Monitor
Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
HighCVSS 7.5WeaponizedEPSS 4%boltcms · boltJul 3, 2025
- CVE-2021-2736731Monitor
Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.
HighCVSS 7.5No exploitEPSS 2%boltcms · boltFeb 17, 2021
- CVE-2020-404125Monitor
The filename of uploaded files vulnerable to stored XSS in Bolt CMS
MediumCVSS 6.1No exploitEPSS 2%boltcms · boltJun 8, 2020
- CVE-2019-955325Monitor
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
MediumCVSS 6.1Proof of conceptEPSS 2%boltcms · boltDec 31, 2019
- CVE-2019-1548524Monitor
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
MediumCVSS 6.1No exploitEPSS 1%boltcms · boltAug 23, 2019
- CVE-2019-1548424Monitor
Bolt before 3.6.10 has XSS via an image's alt or title field.
MediumCVSS 6.1No exploitEPSS 1%boltcms · boltAug 23, 2019
- CVE-2019-1548324Monitor
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
MediumCVSS 6.1No exploitEPSS 1%boltcms · boltAug 23, 2019
- CVE-2019-2005824Monitor
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page.
MediumCVSS 6.1No exploitEPSS 1%boltcms · boltDec 29, 2019
- CVE-2017-1675422Monitor
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventLis
MediumCVSS 5.3No exploitEPSS 2%boltcms · boltNov 9, 2017
- CVE-2020-2892521Monitor
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Y
MediumCVSS 5.3No exploitEPSS 1%boltcms · boltDec 30, 2020
- CVE-2017-1112721Monitor
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
MediumCVSS 5.4No exploitEPSS 1%boltcms · boltJul 17, 2017
- CVE-2017-1112821Monitor
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
MediumCVSS 5.4No exploitEPSS 1%boltcms · boltJul 17, 2017
- CVE-2024-730021Monitor
Bolt CMS Showcase Creation showcases cross site scripting
MediumCVSS 5.3No exploitEPSS 0%boltcms · boltJul 31, 2024
- CVE-2024-729921Monitor
Bolt CMS Entry Preview page cross site scripting
MediumCVSS 5.3No exploitEPSS 0%boltcms · boltJul 31, 2024
- CVE-2020-404018Monitor
CSRF issue on preview pages in Bolt CMS
MediumCVSS 4.3Proof of conceptEPSS 2%boltcms · boltJun 8, 2020