Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
basercms basercms vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2018-18942
In baserCMS prior to 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote malicious users to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
Basercms Basercms
6.5
CVSSv3
CVE-2023-43648
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Basercms Basercms
6.3
CVSSv3
CVE-2015-7769
baserCMS 3.0.2 up to and including 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
Basercms Basercms 3.0.7
Basercms Basercms 3.0.6
Basercms Basercms 3.0.2
Basercms Basercms 3.0.8
Basercms Basercms 3.0.6.1
Basercms Basercms 3.0.5.1
6.1
CVSSv3
CVE-2023-29009
baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.
Basercms Basercms
6.1
CVSSv3
CVE-2022-39325
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified...
Basercms Basercms
6.1
CVSSv3
CVE-2018-0574
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and previous versions versions, baserCMS 3.0.15 and previous versions versions) allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Basercms Basercms
6.1
CVSSv3
CVE-2016-1169
Cross-site scripting (XSS) vulnerability in the Casebook plugin prior to 0.9.4 for baserCMS allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Hiniarata Casebook Plugin
6.1
CVSSv3
CVE-2016-1171
Cross-site scripting (XSS) vulnerability in the Recruit plugin prior to 0.9.3 for baserCMS allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Hiniarata Casebook Plugin
6.1
CVSSv3
CVE-2016-1173
Cross-site scripting (XSS) vulnerability in the Menubook plugin prior to 0.9.3 for baserCMS allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Hiniarata Casebook Plugin
5.4
CVSSv3
CVE-2023-43647
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Basercms Basercms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-36920
buffer overflow
CVE-2024-36913
CVE-2024-5497
CVE-2024-23917
CVE-2024-4956
server-side request forgery
CVE-2024-35468
SSTI
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »