CVE-2013-2651: Boltwire

Medium severity, CVSS 4.3. EPSS: 2.2% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php.

Affected products

  • Boltwire Boltwire: up to and including 3.5; version 3.0 only; version 3.01 only; version 3.02 only; version 3.2.0 only; version 3.2.1 only; …

Published 2013-10-23. Last modified 2026-06-16.