Metrics
Affected Vendors & Products
Mon, 08 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The GitHub repository was archived by the owner and is now read-only. This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | Bolt CMS HTML Attribute TextType.php HTML injection | |
| First Time appeared |
Bolt
Bolt cms |
|
| Weaknesses | CWE-74 CWE-80 |
|
| CPEs | cpe:2.3:a:bolt:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bolt
Bolt cms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-06-08T11:45:08.499Z
Updated: 2026-06-08T13:19:00.864Z
Reserved: 2026-06-07T15:45:50.571Z
Link: CVE-2026-11511
Updated: 2026-06-08T13:18:47.087Z
Status : Deferred
Published: 2026-06-08T13:16:32.007
Modified: 2026-06-08T15:16:42.643
Link: CVE-2026-11511
No data.