CVE 5.1 MEDIUM

Bolt CMS HTML Attribute TextType.php HTML injection_CVE-2026-11511

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The GitHub repository was archived by the owner and is now read-only. This vulnerability only affects products that are no longer supported by the maintainer.

Basic Information

ID CVE-2026-11511
Source VulDB
Published Jun 8, 2026 at 11:45

Affected Product

Vendor Bolt
Product CMS
Version 3.7.0
Affected Versions Bolt CMS 3.7.0
Bolt CMS 3.7.1
Bolt CMS 3.7.2
Bolt CMS 3.7.3
Bolt CMS 3.7.4
Bolt CMS 3.7.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.