VYPR

Vendor CVEs

Basercms

All CVEs

74 total · sorted by risk
  • CVE-2016-4877MedMay 12, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2024-44807MedOct 11, 2024
    risk 0.34cvss 5.3epss 0.00

    A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.

  • CVE-2026-30879MedMar 31, 2026
    risk 0.33cvss 6.1epss 0.00

    baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.

  • CVE-2024-46995MedOct 24, 2024
    risk 0.33cvss 6.1epss 0.00

    baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.

  • CVE-2023-44379MedFeb 22, 2024
    risk 0.33cvss 6.1epss 0.00

    baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.

  • CVE-2023-43647MedOct 30, 2023
    risk 0.33cvss 6.1epss 0.01

    baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.

  • CVE-2023-29009MedOct 27, 2023
    risk 0.33cvss 6.1epss 0.00

    baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.

  • CVE-2022-42486MedDec 7, 2022
    risk 0.31cvss 4.8epss 0.01

    Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

  • CVE-2022-41994MedDec 7, 2022
    risk 0.31cvss 4.8epss 0.01

    Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

  • CVE-2018-18943MedNov 5, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.

  • CVE-2023-51450MedFeb 22, 2024
    risk 0.30cvss 5.6epss 0.01

    baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.

  • CVE-2024-26128MedFeb 22, 2024
    risk 0.28cvss 5.4epss 0.01

    baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.

  • CVE-2021-20683MedMar 26, 2021
    risk 0.28cvss 5.4epss 0.01

    Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

  • CVE-2018-0571MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.

  • CVE-2026-30878MedMar 31, 2026
    risk 0.27cvss 5.3epss 0.00

    baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form…

  • CVE-2023-43648MedOct 30, 2023
    risk 0.25cvss 4.9epss 0.01

    baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.

  • CVE-2023-43649MedOct 30, 2023
    risk 0.24cvss 4.7epss 0.00

    baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.

  • CVE-2022-39325MedNov 25, 2022
    risk 0.23cvss 4.6epss 0.01

    BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an…

  • CVE-2026-65875HigAug 3, 2026
    risk 0.00cvss 7.1epss 0.00

    BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.

  • CVE-2015-5641Oct 6, 2015
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2015-5640Oct 6, 2015
    risk 0.00cvss epss 0.02

    baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.

  • CVE-2012-1248May 15, 2012
    risk 0.00cvss epss 0.03

    app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.

  • CVE-2011-2674Oct 2, 2011
    risk 0.00cvss epss 0.01

    BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.

  • CVE-2011-2673Oct 2, 2011
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Page 2 of 2