Products: 3
Vulnerabilities: 9
Known Exploited: 0
0
Critical Level Threats
4
High Level Threats
2
Medium Level Threats
3
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-71291
Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering
Last Modified: Aug 10, 2026
Published: Aug 05, 2026
CVE-2026-11511
Bolt CMS HTML Attribute TextType.php HTML injection
Last Modified: Jun 08, 2026
Published: Jun 08, 2026
CVE-2026-39229
Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information
Last Modified: May 29, 2026
Published: May 29, 2026
CVE-2025-34086
Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
Last Modified: Apr 07, 2026
Published: Jul 03, 2025
CVE-2024-7300
Bolt CMS Showcase Creation showcases cross site scripting
Last Modified: Feb 13, 2025
Published: Jul 31, 2024
Items Per Page
