| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-10306 | Backup Bolt <= 1.4.1 - Authenticated (Admin+) Arbitrary File Download | backupbolt | Backup Bolt | Low | 3.8 | 2025-10-03 11:17:14 | Deep Dive |
| CVE-2025-49040 | WordPress Backup Bolt plugin <= 1.5.0 - Cross Site Request Forgery (CSRF) vulnerability | Backup Bolt | Backup Bolt | Medium | 4.3 | 2025-08-27 03:24:26 | Deep Dive |
| CVE-2025-34086 | Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename | Bolt | CMS | - | - | 2025-07-03 19:46:16 | Deep Dive |
| CVE-2024-7300 | Bolt CMS Showcase Creation showcases cross site scripting | Bolt | CMS | Low | 3.5 | 2024-07-31 07:00:07 | Deep Dive |
| CVE-2024-7299 | Bolt CMS Entry Preview page cross site scripting | Bolt | CMS | Low | 3.5 | 2024-07-31 06:31:04 | Deep Dive |
| CVE-2023-7236 | Backup Bolt <= 1.3.0 - Sensitive Data Exposure | Unknown | Backup Bolt | 中危 | - | 2024-03-18 19:05:53 | Deep Dive |
| CVE-2023-5214 | CVE-2023-5214 - Privilege Escalation in Puppet Bolt | Puppet | Bolt | Medium | 6.5 | 2023-10-06 17:22:49 | Deep Dive |
| CVE-2022-2394 | Sensitive Parameter Exposure in Puppet Bolt prior to 3.24 | Puppet | Bolt | Medium | 4.1 | 2022-07-19 17:46:48 | Deep Dive |
| CVE-2020-7370 | Danyil Vasilenko Bolt Browser Address Bar Spooofing | Danyil Vasilenko | Bolt Browser | Medium | 4.3 | 2020-10-20 16:40:25 | Deep Dive |
| CVE-2020-4041 | The filename of uploaded files vulnerable to stored XSS in Bolt CMS | bolt | bolt | High | 7.4 | 2020-06-08 22:05:14 | Deep Dive |
| CVE-2020-4040 | CSRF issue on preview pages in Bolt CMS | bolt | bolt | High | 8.6 | 2020-06-08 22:00:16 | Deep Dive |