Skip to content

Bolt CMS

Documentation

Open-source PHP CMS for building and running modern websites as traditional or headless platforms

PHP Latest 6.1.3 · 18d ago Security brief →

Features

  • Built on Symfony with full extensibility
  • YAML configuration for pages, fields, and languages
  • Internationalization with editor in 15 languages
  • Out-of-the-box RESTful and GraphQL APIs
  • Dummy content for development and client demos
  • Licensed rich content editors included

Recent releases

View all 11 releases →
Upgrade now
6.1.3 Security relevant
Auth RCE / SSRF

Folder/file creation/deletion restriction

6.1.2 Breaking risk
Breaking changes
  • Removed @vue/cli-service dependency
Full changelog

What's Changed

  • Upgrade actions to Node24 versions by @bobvandevijver in https://github.com/bolt/core/pull/3706
  • Remove @vue/cli-service by @bobvandevijver in https://github.com/bolt/core/pull/3707
  • Fix MySQL CAST AS TEXT regression by @kouz75 in https://github.com/bolt/core/pull/3710
  • Mysql - Fix field trait item types by @kouz75 in https://github.com/bolt/core/pull/3713

Full Changelog: https://github.com/bolt/core/compare/6.1.1...6.1.2

6.1.1 New feature
Notable features
  • Disable save button during form submission
Full changelog

What's Changed

  • Bump basic-ftp from 5.2.1 to 5.2.2 by @dependabot[bot] in https://github.com/bolt/core/pull/3703
  • Bump follow-redirects from 1.15.11 to 1.16.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3705
  • Disable save button during form submission by @kouz75 in https://github.com/bolt/core/pull/3704

New Contributors

  • @kouz75 made their first contribution in https://github.com/bolt/core/pull/3704

Full Changelog: https://github.com/bolt/core/compare/6.1.0...6.1.1

6.0.2 Bug fix

Fix null author locale when saving new content.

Full changelog

What's Changed

  • Bump lodash from 4.17.21 to 4.17.23 by @dependabot[bot] in https://github.com/bolt/core/pull/3666
  • Bump locutus from 2.0.16 to 2.0.39 by @dependabot[bot] in https://github.com/bolt/core/pull/3667
  • Bump jsonpath from 1.1.1 to 1.2.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3669
  • Bump axios from 1.12.0 to 1.13.5 by @dependabot[bot] in https://github.com/bolt/core/pull/3671
  • Bump jsonpath from 1.2.0 to 1.2.1 by @dependabot[bot] in https://github.com/bolt/core/pull/3672
  • Bump qs from 6.5.3 to 6.5.4 by @dependabot[bot] in https://github.com/bolt/core/pull/3674
  • Bump systeminformation from 5.28.8 to 5.31.1 by @dependabot[bot] in https://github.com/bolt/core/pull/3675
  • Bump webpack from 5.89.0 to 5.105.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3670
  • Bump qs from 6.5.4 to 6.5.5 by @dependabot[bot] in https://github.com/bolt/core/pull/3676
  • Bump ajv from 6.12.6 to 6.14.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3677
  • Bump bn.js from 4.12.0 to 4.12.3 by @dependabot[bot] in https://github.com/bolt/core/pull/3678
  • Bump rollup from 2.79.1 to 2.80.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3680
  • Bump basic-ftp from 5.0.5 to 5.2.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3679
  • Bump minimatch by @dependabot[bot] in https://github.com/bolt/core/pull/3681
  • Bump immutable from 4.3.4 to 4.3.8 by @dependabot[bot] in https://github.com/bolt/core/pull/3683
  • Bump undici from 6.22.0 to 6.24.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3687
  • Bump jsonpath from 1.2.1 to 1.3.0 by @dependabot[bot] in https://github.com/bolt/core/pull/3689
  • Bump yaml from 1.10.2 to 1.10.3 by @dependabot[bot] in https://github.com/bolt/core/pull/3690
  • Bump picomatch from 2.3.1 to 2.3.2 by @dependabot[bot] in https://github.com/bolt/core/pull/3691
  • Bump path-to-regexp and express by @dependabot[bot] in https://github.com/bolt/core/pull/3694
  • Bump brace-expansion from 1.1.12 to 1.1.13 by @dependabot[bot] in https://github.com/bolt/core/pull/3695
  • Bump basic-ftp from 5.2.0 to 5.2.1 by @dependabot[bot] in https://github.com/bolt/core/pull/3698
  • Fix: null author locale when saving new content by @MrWeb in https://github.com/bolt/core/pull/3697
  • Do not allow erusev/parsedown to fix failing cypress tests by @bobvandevijver in https://github.com/bolt/core/pull/3700

New Contributors

  • @MrWeb made their first contribution in https://github.com/bolt/core/pull/3697

Full Changelog: https://github.com/bolt/core/compare/6.0.1...6.0.2

6.0.1 Bug fix

Fixed thumbnail save location bug.

Full changelog

What's Changed

  • Fix thumb save location by @bobvandevijver in https://github.com/bolt/core/pull/3665

Full Changelog: https://github.com/bolt/core/compare/6.0.0...6.0.1

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
582
Forks
181
Languages
PHP Twig JavaScript

Beta — feedback welcome: [email protected]