Git · Bolt · CVE-2026-39229
**Name of the Vulnerable Software and Affected Versions**
Bolt CMS versions prior to 3.7.1
**Description**
An authenticated attacker with low-level privileges can perform SQL Injection via the `order` parameter on content listing pages. This issue occurs within the OrderDirective component and can be used to extract sensitive information.
**Recommendations**
Update Bolt CMS to version 3.7.1 or later.
As a temporary mitigation, restrict access to the content listing pages for low-privileged users.