Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information

Project Subscriptions

Vendors Products
Bolt Cms Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 29 May 2026 17:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Ordering Parameter of Bolt CMS 3.7.0 and Earlier Allowing Data Exfiltration by Authenticated Low‑Privilege Users
First Time appeared Bolt
Bolt bolt Cms
Weaknesses CWE-89
Vendors & Products Bolt
Bolt bolt Cms

Fri, 29 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-29T14:52:34.092Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-29T16:16:26.723

Modified: 2026-05-29T16:32:14.400

Link: CVE-2026-39229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T17:30:04Z

Weaknesses