boltcms kayıtları
boltcms üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %10,5
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %52,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2015-7309Silahlaştırılmış | The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execboltcms · bolt · CWE-74 | Orta6,5 | — | %38,6 | 22 Eyl 2015 |
36İzleyin | CVE-2019-10874Kavram kanıtı | Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary codeboltcms · bolt · CWE-352 | Yüksek8,8 | — | %4,5 | 5 Nis 2019 |
36İzleyin | CVE-2019-9185İstismar yok | Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaboltcms · bolt · CWE-434 | Yüksek8,8 | — | %2,7 | 7 Mar 2019 |
36İzleyin | CVE-2022-31321İstismar yok | The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeratioboltcms · bolt · CWE-20 | Kritik9,1 | — | %0,9 | 1 Ağu 2022 |
31İzleyin | CVE-2025-34086Silahlaştırılmış | Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Renameboltcms · bolt · CWE-94 | Yüksek7,5 | — | %3,6 | 3 Tem 2025 |
31İzleyin | CVE-2021-27367İstismar yok | Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.boltcms · bolt · CWE-22 | Yüksek7,5 | — | %1,7 | 17 Şub 2021 |
25İzleyin | CVE-2020-4041İstismar yok | The filename of uploaded files vulnerable to stored XSS in Bolt CMSboltcms · bolt · CWE-79 | Orta6,1 | — | %2,0 | 8 Haz 2020 |
25İzleyin | CVE-2019-9553Kavram kanıtı | Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.boltcms · bolt · CWE-79 | Orta6,1 | — | %1,8 | 31 Ara 2019 |
24İzleyin | CVE-2019-15485İstismar yok | Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.boltcms · bolt · CWE-79 | Orta6,1 | — | %0,9 | 23 Ağu 2019 |
24İzleyin | CVE-2019-15484İstismar yok | Bolt before 3.6.10 has XSS via an image's alt or title field.boltcms · bolt · CWE-79 | Orta6,1 | — | %0,9 | 23 Ağu 2019 |
24İzleyin | CVE-2019-15483İstismar yok | Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.boltcms · bolt · CWE-79 | Orta6,1 | — | %0,9 | 23 Ağu 2019 |
24İzleyin | CVE-2019-20058İstismar yok | Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page.boltcms · bolt · CWE-79 | Orta6,1 | — | %0,7 | 29 Ara 2019 |
22İzleyin | CVE-2017-16754İstismar yok | Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventLisboltcms · bolt · CWE-732 | Orta5,3 | — | %1,8 | 9 Kas 2017 |
21İzleyin | CVE-2020-28925İstismar yok | Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Yboltcms · bolt | Orta5,3 | — | %1,1 | 30 Ara 2020 |
21İzleyin | CVE-2017-11127İstismar yok | Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.boltcms · bolt · CWE-79 | Orta5,4 | — | %0,6 | 17 Tem 2017 |
21İzleyin | CVE-2017-11128İstismar yok | Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.boltcms · bolt · CWE-79 | Orta5,4 | — | %0,6 | 17 Tem 2017 |
21İzleyin | CVE-2024-7300İstismar yok | Bolt CMS Showcase Creation showcases cross site scriptingboltcms · bolt · CWE-79 | Orta5,3 | — | %0,4 | 31 Tem 2024 |
21İzleyin | CVE-2024-7299İstismar yok | Bolt CMS Entry Preview page cross site scriptingboltcms · bolt · CWE-79 | Orta5,3 | — | %0,4 | 31 Tem 2024 |
18İzleyin | CVE-2020-4040Kavram kanıtı | CSRF issue on preview pages in Bolt CMSboltcms · bolt · CWE-352 | Orta4,3 | — | %1,8 | 8 Haz 2020 |
- CVE-2015-730938İzleyin
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to exec
OrtaCVSS 6,5SilahlaştırılmışEPSS %39boltcms · bolt22 Eyl 2015
- CVE-2019-1087436İzleyin
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code
YüksekCVSS 8,8Kavram kanıtıEPSS %5boltcms · bolt5 Nis 2019
- CVE-2019-918536İzleyin
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by rena
YüksekCVSS 8,8İstismar yokEPSS %3boltcms · bolt7 Mar 2019
- CVE-2022-3132136İzleyin
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeratio
KritikCVSS 9,1İstismar yokEPSS %1boltcms · bolt1 Ağu 2022
- CVE-2025-3408631İzleyin
Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
YüksekCVSS 7,5SilahlaştırılmışEPSS %4boltcms · bolt3 Tem 2025
- CVE-2021-2736731İzleyin
Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.
YüksekCVSS 7,5İstismar yokEPSS %2boltcms · bolt17 Şub 2021
- CVE-2020-404125İzleyin
The filename of uploaded files vulnerable to stored XSS in Bolt CMS
OrtaCVSS 6,1İstismar yokEPSS %2boltcms · bolt8 Haz 2020
- CVE-2019-955325İzleyin
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
OrtaCVSS 6,1Kavram kanıtıEPSS %2boltcms · bolt31 Ara 2019
- CVE-2019-1548524İzleyin
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
OrtaCVSS 6,1İstismar yokEPSS %1boltcms · bolt23 Ağu 2019
- CVE-2019-1548424İzleyin
Bolt before 3.6.10 has XSS via an image's alt or title field.
OrtaCVSS 6,1İstismar yokEPSS %1boltcms · bolt23 Ağu 2019
- CVE-2019-1548324İzleyin
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
OrtaCVSS 6,1İstismar yokEPSS %1boltcms · bolt23 Ağu 2019
- CVE-2019-2005824İzleyin
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page.
OrtaCVSS 6,1İstismar yokEPSS %1boltcms · bolt29 Ara 2019
- CVE-2017-1675422İzleyin
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventLis
OrtaCVSS 5,3İstismar yokEPSS %2boltcms · bolt9 Kas 2017
- CVE-2020-2892521İzleyin
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Y
OrtaCVSS 5,3İstismar yokEPSS %1boltcms · bolt30 Ara 2020
- CVE-2017-1112721İzleyin
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
OrtaCVSS 5,4İstismar yokEPSS %1boltcms · bolt17 Tem 2017
- CVE-2017-1112821İzleyin
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
OrtaCVSS 5,4İstismar yokEPSS %1boltcms · bolt17 Tem 2017
- CVE-2024-730021İzleyin
Bolt CMS Showcase Creation showcases cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0boltcms · bolt31 Tem 2024
- CVE-2024-729921İzleyin
Bolt CMS Entry Preview page cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0boltcms · bolt31 Tem 2024
- CVE-2020-404018İzleyin
CSRF issue on preview pages in Bolt CMS
OrtaCVSS 4,3Kavram kanıtıEPSS %2boltcms · bolt8 Haz 2020