Skip to main content

Vendor archive

basercms CVEs

Beta · best-effort

68 CVEs tagged to vendor basercms8 Critical, 27 High, 33 Medium, 0 Low, 0 Unrated.

CVE-2026-32734

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been patched in version 5.2.3.

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-30940

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_f…

CVSS 7.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-30880

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.…

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-30879

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-30878

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the correspond…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-30877

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticate…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-27697

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been patched in version 5.2.3.

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-21861

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated adm…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-32957

Published Mar 31, 2026

baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted.…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46998

Published Oct 24, 2024

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the iss…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46996

Published Oct 24, 2024

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46995

Published Oct 24, 2024

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46994

Published Oct 24, 2024

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes this is…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26128

Published Feb 22, 2024

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51450

Published Feb 22, 2024

baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44379

Published Feb 22, 2024

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for thi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43792

Published Oct 30, 2023

baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no k…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43649

Published Oct 30, 2023

baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43648

Published Oct 30, 2023

baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Versi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43647

Published Oct 30, 2023

baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29009

Published Oct 27, 2023

baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25655

Published Mar 23, 2023

baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25654

Published Mar 23, 2023

baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42486

Published Dec 7, 2022

Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to i…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41994

Published Dec 7, 2022

Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inj…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 68 CVEsPage 1 of 3