Bolt maintains a lightweight open-source content management system focused on simplicity and ease of deployment, with a narrow but notably represented product footprint. The vendor's vulnerability exposure centers on its core CMS product and reflects application-layer input-handling weaknesses, particularly code injection and cross-site scripting issues that are common to web-based templating and content systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bolt over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36532HIGH Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve rem | Sep 16, 2022 | 8.8 | 43 | NO | NO |
CVE-2021-40219HIGH Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to | Apr 11, 2022 | 8.8 | 31 | NO | NO |
CVE-2018-19933MEDIUM Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. | Dec 17, 2018 | 6.1 | 31 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bolt.
Media articles that mention a CVE ID that affects a product developed by Bolt — matched by CVE ID, not by vendor name.