📦

bolt

Vendor: boltcms

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 4 Remote Access
Total CVEs 70 Total Indexed
Avg. EPSS 6.74% Exploit Prob.
Latest CVE CVE-2025-34086 Jul 03

Security Vulnerability Index

Page 2 / 7
6.1 CVSS

Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040

EPSS: 0.33%
6.1 CVSS

Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.

EPSS: 0.30%
6.1 CVSS

Bolt before 3.6.10 has XSS via an image's alt or title field.

EPSS: 0.30%
6.1 CVSS

Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.

EPSS: 0.22%
8.8 CVSS
CVE-2019-10874
RCE Exploit Found

Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.

EPSS: 0.39%
8.8 CVSS

Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.

EPSS: 1.04%
5.3 CVSS

Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.

EPSS: 0.38%
5.4 CVSS

Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.

EPSS: 0.28%
5.4 CVSS

Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.

EPSS: 0.28%
6.5 CVSS
CVE-2015-7309
RCE Exploit Found

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

EPSS: 60.27%