CVE Tools

Boltcms

10 CVEs tracked since 2015. Since Sep 2015, none of them reached CISA KEV.

Boltcms CVEs per month

Sep 2015 to Jun 2020. Point at a month, or focus the strip and use the arrow keys.
Boltcms CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0910
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-0720
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-0830
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-1220
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0620

Products

The products that kept showing up in Boltcms's monthly top three, with their CVEs summed over those months.

  1. Bolt105 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Boltcms.

  1. CVE-2025-34086Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename8.8
  2. CVE-2024-7300Bolt CMS Showcase Creation showcases cross site scripting3.5
  3. CVE-2024-7299Bolt CMS Entry Preview page cross site scripting3.5
  4. CVE-2022-31321The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.9.1
  5. CVE-2021-27367Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.7.5
  6. CVE-2020-28925Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.5.3
  7. CVE-2020-4041The filename of uploaded files vulnerable to stored XSS in Bolt CMS7.4
  8. CVE-2020-4040CSRF issue on preview pages in Bolt CMS8.6
  9. CVE-2019-9553Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.6.1
  10. CVE-2019-20058Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use ...6.1
  11. CVE-2019-15485Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.6.1
  12. CVE-2019-15484Bolt before 3.6.10 has XSS via an image's alt or title field.6.1
  13. CVE-2019-15483Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.6.1
  14. CVE-2019-10874Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable ext...8.8
  15. CVE-2019-9185Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.8.8

The record

Peak rank
#68 in Sep 2015
Busiest month shown
Aug 2019, 3 CVEs
Months with a KEV entry
0 since Sep 2015
Monthly snapshots
5 since 2015
Boltcms's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store