An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS0yZzIzLXFtbXAtZnZtcs4AAjK6

Moderate EPSS: 0.00993% (0.75881 Percentile) EPSS:

Bolt Cross-site Scripting via the slug, teaser or title parameters

Affected Packages Affected Versions Fixed Versions
packagist:bolt/bolt = 3.6.4 No known fixed version
25 Dependent packages
232 Dependent repositories
210,457 Downloads total

Affected Version Ranges

All affected versions

Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.

References: