Bolt CMS SQL Injection Vulnerability in Order Parameter

Vulnerability

A SQL injection vulnerability has been identified in Bolt CMS versions through 3.7.0. The issue resides in the 'order' parameter of the content listing pages, specifically within the OrderDirective component. This vulnerability allows authenticated attackers with low-level privileges to exploit the parameter, leading to the extraction of sensitive information from the database.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive database information, including administrative password hashes, and potentially allow for a complete database compromise.

Reproduction

To reproduce this vulnerability, log into the Bolt CMS backend with a low-privileged account, such as an Editor. Then, navigate to the content overview pages and inject a time-based SQL payload into the 'order' parameter. If successful, a delay in the server response time will indicate that the SQL injection has been exploited.

Remediation

Users are advised to update to Bolt CMS version 3.7.1 or later, where this vulnerability has been addressed.

Added: May 29, 2026, 4:26 PM
Updated: May 29, 2026, 4:26 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.8
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.