This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Bolt First view 2017-07-17
Product Bolt Cms Last view 2022-09-16
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:bolt:bolt_cms:3.2.14:*:*:*:*:*:*:* 5
cpe:2.3:a:bolt:bolt_cms:*:*:*:*:*:*:*:* 3

Related : CVE

  Date Alert Description
8.8 2022-09-16 CVE-2022-36532

Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution.

8.8 2022-04-11 CVE-2021-40219

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.

6.1 2018-12-17 CVE-2018-19933

Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.

5.4 2017-07-17 CVE-2017-11128

Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.

5.4 2017-07-17 CVE-2017-11127

Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.

CWE : Common Weakness Enumeration

%idName
75% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
25% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')