Vulnerabilities in bolt
7 resultsVexday analysis
O fornecedor Bolt apresenta uma superfície de risco reduzida com apenas 2 CVEs catalogadas, nenhuma sob ataque ativo ou com severidade crítica. A fraqueza dominante identificada é CWE-352 (Cross-Site Request Forgery), um vetor clássico de segurança que merece atenção, mas sem pressão imediata dado que não há exploração em campo e nenhuma vulnerabilidade recente foi descoberta nos últimos 90 dias.
CVE-2025-34086HIGHBolt CMS Authenticated Remote Code Execution via Profile Injection and File RenameEPSS 2.2%CVE-2020-4041HIGHThe filename of uploaded files vulnerable to stored XSS in Bolt CMSEPSS 2.0%CVE-2020-4040HIGHCSRF issue on preview pages in Bolt CMSEPSS 1.8%CVE-2026-71291HIGHBolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field RenderingEPSS 0.5%CVE-2024-7300MEDIUMBolt CMS Showcase Creation showcases cross site scriptingEPSS 0.4%CVE-2024-7299MEDIUMBolt CMS Entry Preview page cross site scriptingEPSS 0.4%CVE-2026-11511MEDIUMBolt CMS HTML Attribute TextType.php HTML injectionEPSS 0.2%