CVE-2026-39229

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information

Published 2026-05-29. Last modified 2026-07-21.