Boltcms develops a modestly represented content-management system that, despite a narrow product footprint, occupies a meaningful position among web-application platforms. The recurring vulnerabilities affecting Bolt cluster around input-handling and code-generation weaknesses—cross-site scripting, cross-site request forgery, unrestricted file uploads, code injection, and input validation flaws—that are characteristic of web frameworks accepting user-generated content and administrative input, and the vendor's disclosures have an elevated tendency to acquire public exploit code. Defenders deploying Bolt should prioritize input-sanitization and upload-control mechanisms; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boltcms over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7309MEDIUM The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted | Sep 22, 2015 | 6.5 | 61 | NO | YES |
CVE-2019-10874HIGH Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to inclu | Apr 5, 2019 | 8.8 | 41 | NO | YES |
CVE-2025-34086HIGH Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials can | Jul 3, 2025 | 8.8 | 38 | NO | YES |
CVE-2019-9553MEDIUM Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933. | Dec 31, 2019 | 6.1 | 31 | NO | YES |
CVE-2022-31321CRITICAL The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via | Aug 1, 2022 | 9.1 | 29 | NO | NO |
CVE-2021-27367HIGH Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal. | Feb 17, 2021 | 7.5 | 23 | NO | NO |
CVE-2019-9185HIGH Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have | Mar 7, 2019 | 8.8 | 22 | NO | NO |
CVE-2024-7300MEDIUM A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creati | Jul 31, 2024 | 5.4 | 21 | NO | NO |
CVE-2019-20058MEDIUM Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never | Dec 29, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-15485MEDIUM Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. | Aug 23, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boltcms.
Media articles that mention a CVE ID that affects a product developed by Boltcms — matched by CVE ID, not by vendor name.