CVE-2020-28925: Boltcms Bolt

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.

Affected products

  • Boltcms Bolt: before 3.7.2 (fixed in 3.7.2)

Published 2020-12-30. Last modified 2026-06-17.