PT-2026-44900 · Git · Bolt

·

CVE-2026-39229

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bolt CMS versions prior to 3.7.1
Description An authenticated attacker with low-level privileges can perform SQL Injection via the order parameter on content listing pages. This issue occurs within the OrderDirective component and can be used to extract sensitive information.
Recommendations Update Bolt CMS to version 3.7.1 or later. As a temporary mitigation, restrict access to the content listing pages for low-privileged users.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39229

Affected Products

Bolt