Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
basercms basercms vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2018-18942
In baserCMS prior to 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote malicious users to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
Basercms Basercms
6.5
CVSSv3
CVE-2023-43648
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Basercms Basercms
6.3
CVSSv3
CVE-2015-7769
baserCMS 3.0.2 up to and including 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
Basercms Basercms 3.0.7
Basercms Basercms 3.0.6
Basercms Basercms 3.0.2
Basercms Basercms 3.0.8
Basercms Basercms 3.0.6.1
Basercms Basercms 3.0.5.1
6.1
CVSSv3
CVE-2023-29009
baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.
Basercms Basercms
6.1
CVSSv3
CVE-2022-39325
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified...
Basercms Basercms
6.1
CVSSv3
CVE-2018-0574
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and previous versions versions, baserCMS 3.0.15 and previous versions versions) allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Basercms Basercms
6.1
CVSSv3
CVE-2016-1169
Cross-site scripting (XSS) vulnerability in the Casebook plugin prior to 0.9.4 for baserCMS allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Hiniarata Casebook Plugin
6.1
CVSSv3
CVE-2016-1171
Cross-site scripting (XSS) vulnerability in the Recruit plugin prior to 0.9.3 for baserCMS allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Hiniarata Casebook Plugin
6.1
CVSSv3
CVE-2016-1173
Cross-site scripting (XSS) vulnerability in the Menubook plugin prior to 0.9.3 for baserCMS allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Hiniarata Casebook Plugin
5.4
CVSSv3
CVE-2023-43647
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.
Basercms Basercms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »