Known Vulnerabilities for Bolt Cms by Bolt
Listed below are 3 of the newest known vulnerabilities associated with "Bolt Cms" by "Bolt".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42072 json | Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. ... | Not Provided | 2026-05-08 | 2026-05-12 |
| CVE-2026-39229 json | Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker ... | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-35565 json | Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 De... | Not Provided | 2026-04-13 | 2026-04-13 |
| CVE-2026-11511 json | A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2025-49040 json | Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This... | Not Provided | 2025-08-27 | 2026-04-23 |
| CVE-2025-10306 json | The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up ... | Not Provided | 2025-10-03 | 2026-04-08 |
| CVE-2022-36532 json | Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileg... | 8.8 - HIGH | 2022-09-16 | 2022-09-19 |
| CVE-2021-40219 json | Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme... | 8.8 - HIGH | 2022-04-11 | 2022-04-15 |
| CVE-2018-19933 json | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Ent... | 6.1 - MEDIUM | 2018-12-17 | 2019-01-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bolt | Bolt Cms | 3.6.3 | |||
| Application | Bolt | Bolt Cms | 3.6.2 | |||
| Application | Bolt | Bolt Cms | 3.6.1 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.6.0 | |||
| Application | Bolt | Bolt Cms | 3.5.6 | |||
| Application | Bolt | Bolt Cms | 3.5.5 | |||
| Application | Bolt | Bolt Cms | 3.5.4 | |||
| Application | Bolt | Bolt Cms | 3.5.3 | |||
| Application | Bolt | Bolt Cms | 3.5.2 | |||
| Application | Bolt | Bolt Cms | 3.5.1 | |||
| Application | Bolt | Bolt Cms | 3.5.0 | |||
| Application | Bolt | Bolt Cms | 3.4.9 | |||
| Application | Bolt | Bolt Cms | 3.4.8 |