Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information
History

Fri, 29 May 2026 17:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Ordering Parameter of Bolt CMS 3.7.0 and Earlier Allowing Data Exfiltration by Authenticated Low‑Privilege Users
First Time appeared Bolt
Bolt bolt Cms
Weaknesses CWE-89
Vendors & Products Bolt
Bolt bolt Cms

Fri, 29 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-29T14:52:34.092Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-29T16:16:26.723

Modified: 2026-05-29T16:32:14.400

Link: CVE-2026-39229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T17:30:04Z