Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2020-4040
Disclosure Date: June 08, 2020 (last updated February 21, 2025)
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a preview. This has been fixed in Bolt 3.7.1
0
Attacker Value
Unknown
CVE-2019-9553
Disclosure Date: December 31, 2019 (last updated November 27, 2024)
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
0
Attacker Value
Unknown
CVE-2019-15485
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
0
Attacker Value
Unknown
CVE-2019-15483
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
0
Attacker Value
Unknown
CVE-2019-15484
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Bolt before 3.6.10 has XSS via an image's alt or title field.
0
Attacker Value
Unknown
CVE-2019-20058
Disclosure Date: June 19, 2019 (last updated November 08, 2023)
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040
0
Attacker Value
Unknown
CVE-2019-10874
Disclosure Date: April 05, 2019 (last updated November 27, 2024)
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.
0
Attacker Value
Unknown
CVE-2019-9185
Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.
0
Attacker Value
Unknown
CVE-2018-19904
Disclosure Date: December 31, 2018 (last updated November 27, 2024)
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.
0
Attacker Value
Unknown
CVE-2018-19903
Disclosure Date: December 31, 2018 (last updated November 27, 2024)
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page title field.
0