VYPR

Basercms

by Basercms

Source repositories

CVEs (73)

  • CVE-2026-21861CriMar 31, 2026
    risk 0.52cvss 9.1epss 0.02

    baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of…

  • CVE-2021-41243CriNov 26, 2021
    risk 0.52cvss 9.1epss 0.02

    There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability…

  • CVE-2025-32957HigMar 31, 2026
    risk 0.50cvss 8.7epss 0.01

    baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using require_once without validating or restricting the…

  • CVE-2021-39136HigAug 25, 2021
    risk 0.50cvss 8.7epss 0.01

    baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible.…

  • CVE-2017-10843HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.01

    baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.

  • CVE-2021-20682HigMar 26, 2021
    risk 0.47cvss 7.2epss 0.02

    baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-18942HigNov 5, 2018
    risk 0.47cvss 7.2epss 0.02

    In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.

  • CVE-2024-46998HigOct 24, 2024
    risk 0.46cvss 7.1epss 0.00

    baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the issue.

  • CVE-2021-41279HigNov 26, 2021
    risk 0.43cvss 7.7epss 0.02

    BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted zip files capable of path traversal on the host operating system. This is a vulnerability that needs to be…

  • CVE-2020-15276HigOct 30, 2020
    risk 0.43cvss 7.7epss 0.01

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

  • CVE-2020-15159HigAug 28, 2020
    risk 0.43cvss 7.6epss 0.02

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and…

  • CVE-2024-46996MedOct 24, 2024
    risk 0.41cvss 6.3epss 0.00

    baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.

  • CVE-2020-15273HigOct 30, 2020
    risk 0.41cvss 7.3epss 0.01

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be executed by entering specific characters in…

  • CVE-2020-15155HigAug 28, 2020
    risk 0.41cvss 7.3epss 0.01

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

  • CVE-2020-15154HigAug 28, 2020
    risk 0.41cvss 7.3epss 0.01

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php,…

  • CVE-2015-7769MedFeb 19, 2016
    risk 0.41cvss 6.3epss 0.01

    baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

  • CVE-2026-30940HigMar 31, 2026
    risk 0.40cvss 7.2epss 0.01

    baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../…

  • CVE-2020-15277HigOct 30, 2020
    risk 0.40cvss 7.2epss 0.02

    baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.

  • CVE-2018-0574MedJun 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1173MedApr 6, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.