Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown

CVE-2017-16754

Disclosure Date: November 10, 2017 (last updated November 26, 2024)
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
0
Attacker Value
Unknown

CVE-2017-11128

Disclosure Date: July 17, 2017 (last updated February 15, 2025)
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
0
Attacker Value
Unknown

CVE-2017-11127

Disclosure Date: July 17, 2017 (last updated February 15, 2025)
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
0
Attacker Value
Unknown

CVE-2015-7309

Disclosure Date: September 22, 2015 (last updated October 05, 2023)
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.
0