Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
basercms basercms vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2021-20683
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions before 4.4.5 allows remote authenticated malicious users to inject an arbitrary script via unspecified vectors.
Basercms Basercms
6.1
CVSSv3
CVE-2023-29009
baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.
Basercms Basercms
NA
CVE-2015-5641
SQL injection vulnerability in baserCMS prior to 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Basercms Basercms
7.2
CVSSv3
CVE-2018-18942
In baserCMS prior to 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote malicious users to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
Basercms Basercms
5.4
CVSSv3
CVE-2023-43647
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Basercms Basercms
6.5
CVSSv3
CVE-2023-43648
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Basercms Basercms
9.8
CVSSv3
CVE-2023-43649
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Basercms Basercms
9.8
CVSSv3
CVE-2023-43792
baserCMS is a website development framework. In versions 4.6.0 up to and including 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
Basercms Basercms
7.6
CVSSv3
CVE-2020-15159
baserCMS 4.3.6 and previous versions is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController...
Basercms Basercms
8.7
CVSSv3
CVE-2020-15276
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
Basercms Basercms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »