Products
Government
Resources
Community
Company
Partners
Sign In / Join
Sign In
Go back
Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
severity
high
date
July 3, 2025
Affecting
Bolt CMS <= 3.7.0
CVE
CVE-2025-34086
CVE type
Code Injection
CVSS
7.5
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References
Vendor EOL Statement
Vendor Patch
Metasploit Module
Credit
Sivanesh Ashok