Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown
CVE-2017-16754
Disclosure Date: November 10, 2017 (last updated November 26, 2024)
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
0
Attacker Value
Unknown
CVE-2017-11128
Disclosure Date: July 17, 2017 (last updated February 15, 2025)
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
0
Attacker Value
Unknown
CVE-2017-11127
Disclosure Date: July 17, 2017 (last updated February 15, 2025)
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
0
Attacker Value
Unknown
CVE-2015-7309
Disclosure Date: September 22, 2015 (last updated October 05, 2023)
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.
0