PT-2026-47278 · Bolt Cms · Bolt Cms

Geochen

·

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-11511

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bolt CMS versions prior to 3.7.6
Description An issue exists in the HTML Attribute Handler component within the file src/Storage/Field/Type/TextType.php. A remote attacker can perform HTML injection by manipulating the style argument. This affects products that are no longer supported by the maintainer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-11511

Affected Products

Bolt Cms