CVE-2026-11511

3.5 LOW
Published: June 08, 2026 Modified: June 08, 2026
View on NVD

Description

A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The GitHub repository was archived by the owner and is now read-only. This vulnerability only affects products that are no longer supported by the maintainer.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://vuldb.com/submit/836106
Source: cna@vuldb.com
https://vuldb.com/vuln/369131
Source: cna@vuldb.com
https://vuldb.com/submit/836106
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

5 reference(s) from NVD

Quick Stats

CVSS v3 Score
3.5 / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)