CVE-2017-16754: Boltcms Bolt

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.

Affected products

  • Boltcms Bolt: up to and including 3.3.5

Published 2017-11-10. Last modified 2026-06-17.