CVE-2018-19933: Bolt CMS

Medium severity, CVSS 6.1. EPSS: 3.5% chance of exploitation in the next 30 days.

Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.

Affected products

  • Bolt Bolt CMS: before 3.6.2 (fixed in 3.6.2)

Published 2018-12-17. Last modified 2026-06-17.