{"api_version":"v1","generated_at":"2026-10-07T01:45:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-bolt-cms-5967eb09af7c","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cms","name":"CMS","next_cursor":null,"observations":[{"affected":"3.7.0; 3.7.1; 3.7.2; 3.7.3; 3.7.4; 3.7.5","affected_versions_present":true,"cve_id":"CVE-2026-11511","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-11511","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-08T13:19:00.864Z","patch_url":"","primary_source":"","published":"2026-06-08T11:45:08.499Z"},{"affected":"\u2264 3.7.0","affected_versions_present":true,"cve_id":"CVE-2025-34086","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34086","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-15T11:14:37.061Z","patch_url":"","primary_source":"","published":"2025-07-03T19:46:16.190Z"},{"affected":"3.7.1","affected_versions_present":true,"cve_id":"CVE-2024-7300","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-7300","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-19T13:34:37.679Z","patch_url":"","primary_source":"","published":"2024-07-31T07:00:06.610Z"},{"affected":"3.7.1","affected_versions_present":true,"cve_id":"CVE-2024-7299","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-7299","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-07-31T15:32:33.267Z","patch_url":"","primary_source":"","published":"2024-07-31T06:31:04.296Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Bolt"}}
