CVE-2026-39229

Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information
Configurations

No configuration.

History

21 Jul 2026, 15:10

Type Values Removed Values Added
Summary
  • (es) Bolt CMS hasta la versión 3.7.0 permite inyección SQL en el parámetro 'order' de las páginas de listado de contenido. Un atacante autenticado con privilegios de bajo nivel puede explotar esto a través del componente OrderDirective. Esto permite la extracción de información sensible.

29 May 2026, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-89

29 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 16:16

Updated : 2026-07-21 15:10


NVD link : CVE-2026-39229

Mitre link : CVE-2026-39229

CVE.ORG link : CVE-2026-39229


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')