VYPR

Basercms

by Basercms

Source repositories

CVEs (70)

  • CVE-2020-15276Oct 30, 2020
    risk 0.00cvss epss 0.01

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

  • CVE-2020-15277Oct 30, 2020
    risk 0.00cvss epss 0.02

    baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.

  • CVE-2020-15159Aug 28, 2020
    risk 0.00cvss epss 0.02

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and…

  • CVE-2020-15155Aug 28, 2020
    risk 0.00cvss epss 0.01

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

  • CVE-2020-15154Aug 28, 2020
    risk 0.00cvss epss 0.01

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php,…

  • CVE-2015-5641Oct 6, 2015
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2015-5640Oct 6, 2015
    risk 0.00cvss epss 0.02

    baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.

  • CVE-2012-1248May 15, 2012
    risk 0.00cvss epss 0.03

    app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.

  • CVE-2011-2674Oct 2, 2011
    risk 0.00cvss epss 0.01

    BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.

  • CVE-2011-2673Oct 2, 2011
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Page 4 of 4