Vulnerabilities > Boltcms > Bolt > 3.7.1

DATE CVE VULNERABILITY TITLE RISK
2024-07-31 CVE-2024-7299 Unspecified vulnerability in Boltcms Bolt 3.7.1
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1.
network
low complexity
boltcms
5.4
2024-07-31 CVE-2024-7300 Unspecified vulnerability in Boltcms Bolt 3.7.1
A vulnerability classified as problematic has been found in Bolt CMS 3.7.1.
network
low complexity
boltcms
5.4
2022-08-01 CVE-2022-31321 Improper Input Validation vulnerability in Boltcms Bolt
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
network
low complexity
boltcms CWE-20
critical
9.1
2021-02-17 CVE-2021-27367 Path Traversal vulnerability in Boltcms Bolt
Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal.
network
low complexity
boltcms CWE-22
7.5
2020-12-30 CVE-2020-28925 Unspecified vulnerability in Boltcms Bolt
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.
network
low complexity
boltcms
5.3