Basercms
by Basercms
Source repositories
CVEs (74)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-51450 | Med | 0.30 | 5.6 | 0.01 | Feb 22, 2024 | baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability. | ||
| CVE-2024-26128 | Med | 0.28 | 5.4 | 0.01 | Feb 22, 2024 | baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability. | ||
| CVE-2021-20683 | Med | 0.28 | 5.4 | 0.01 | Mar 26, 2021 | Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors. | ||
| CVE-2018-0571 | Med | 0.28 | 4.3 | 0.01 | Jun 26, 2018 | baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files. | ||
| CVE-2016-4883 | Med | 0.28 | 5.4 | 0.01 | May 12, 2017 | Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2026-30878 | Med | 0.27 | 5.3 | 0.00 | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form… | ||
| CVE-2023-43648 | Med | 0.25 | 4.9 | 0.01 | Oct 30, 2023 | baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue. | ||
| CVE-2023-43649 | Med | 0.24 | 4.7 | 0.00 | Oct 30, 2023 | baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue. | ||
| CVE-2022-39325 | Med | 0.23 | 4.6 | 0.01 | Nov 25, 2022 | BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an… | ||
| CVE-2015-5641 | 0.00 | — | 0.02 | Oct 6, 2015 | SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2015-5640 | 0.00 | — | 0.02 | Oct 6, 2015 | baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request. | |||
| CVE-2012-1248 | 0.00 | — | 0.03 | May 15, 2012 | app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain. | |||
| CVE-2011-2674 | 0.00 | — | 0.01 | Oct 2, 2011 | BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors. | |||
| CVE-2011-2673 | 0.00 | — | 0.02 | Oct 2, 2011 | Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
- risk 0.30cvss 5.6epss 0.01
baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.
- risk 0.28cvss 5.4epss 0.01
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.
- risk 0.28cvss 5.4epss 0.01
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.
- risk 0.28cvss 5.4epss 0.01
Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.27cvss 5.3epss 0.00
baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form…
- risk 0.25cvss 4.9epss 0.01
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
- risk 0.24cvss 4.7epss 0.00
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.
- risk 0.23cvss 4.6epss 0.01
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an…
- CVE-2015-5641Oct 6, 2015risk 0.00cvss —epss 0.02
SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
- CVE-2015-5640Oct 6, 2015risk 0.00cvss —epss 0.02
baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.
- CVE-2012-1248May 15, 2012risk 0.00cvss —epss 0.03
app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.
- CVE-2011-2674Oct 2, 2011risk 0.00cvss —epss 0.01
BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.
- CVE-2011-2673Oct 2, 2011risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Page 4 of 4