Products: 3
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    2
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-71291

    Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering

    Last Modified: Aug 10, 2026
    Published: Aug 05, 2026

    CVE-2026-11511

    Bolt CMS HTML Attribute TextType.php HTML injection

    Last Modified: Jun 08, 2026
    Published: Jun 08, 2026

    CVE-2026-39229

    Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information

    Last Modified: May 29, 2026
    Published: May 29, 2026

    CVE-2025-34086

    Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename

    Last Modified: Apr 07, 2026
    Published: Jul 03, 2025

    CVE-2024-7300

    Bolt CMS Showcase Creation showcases cross site scripting

    Last Modified: Feb 13, 2025
    Published: Jul 31, 2024
    Items Per Page
    Bolt Vulnerabilities & Security CVEs | CVE-DB