basercms records
68 published records for vendor basercms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 72.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')8
- CWE-434 Unrestricted Upload of File with Dangerous Type6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
68 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-10842No exploit | SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands basercms · basercms · CWE-89 | Critical9.8 | — | 1.8% | Aug 28, 2017 |
39Monitor | CVE-2023-25654No exploit | baserCMS File Uploader Remote Code Execution (RCE) vulnerabilitybasercms · basercms · CWE-434 | Critical9.8 | — | 1.5% | Mar 23, 2023 |
39Monitor | CVE-2023-25655No exploit | baserCMS allows any file to be uploadedbasercms · basercms · CWE-434 | Critical9.8 | — | 1.1% | Mar 23, 2023 |
39Monitor | CVE-2023-43792No exploit | baserCMS Code Injection Vulnerability in Mail Form Featurebasercms · basercms · CWE-94 | Critical9.8 | — | 0.6% | Oct 30, 2023 |
39Monitor | CVE-2023-43649No exploit | baserCMS CSRF vulnerability in Content preview Featurebasercms · basercms · CWE-352 | Critical9.8 | — | 0.3% | Oct 30, 2023 |
37Monitor | CVE-2026-30880No exploit | baserCMS: OS command injection vulnerability in installerbasercms · basercms · CWE-78 | Critical9.2 | — | 2.2% | Mar 30, 2026 |
36Monitor | CVE-2021-41243No exploit | OS Command Injection Vulnerability and Potential Zip Slip Vulnerabilitybasercms · basercms · CWE-78 | High8.8 | — | 2.2% | Nov 26, 2021 |
35Monitor | CVE-2021-41279No exploit | Zip Slip Vulnerability in BaserCMSbasercms · basercms · CWE-22 | High8.8 | — | 1.6% | Nov 26, 2021 |
35Monitor | CVE-2018-0569No exploit | baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbibasercms · basercms · CWE-78 | High8.8 | — | 1.5% | Jun 26, 2018 |
35Monitor | CVE-2017-10844No exploit | baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.basercms · basercms · CWE-94 | High8.8 | — | 1.5% | Aug 28, 2017 |
35Monitor | CVE-2016-4881No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the autbasercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4878No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication basercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4884No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the autbasercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4882No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication basercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4887No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack thebasercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4886No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the autbasercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4885No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the autbasercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4876No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication basercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
35Monitor | CVE-2016-4879No exploit | Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the autbasercms · basercms · CWE-352 | High8.8 | — | 0.9% | May 12, 2017 |
34Monitor | CVE-2020-15276No exploit | Cross Site Scripting in baserCMSbasercms · basercms · CWE-79 | High8.7 | — | 1.0% | Oct 30, 2020 |
32Monitor | CVE-2018-0572No exploit | baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass accesbasercms · basercms | High8.1 | — | 1.6% | Jun 26, 2018 |
32Monitor | CVE-2023-51450No exploit | baserCMS OS command injection vulnerability in Installerbasercms · basercms · CWE-78 | High8.1 | — | 1.5% | Feb 22, 2024 |
32Monitor | CVE-2020-15273No exploit | Cross-Site Scripting in baserCMSbasercms · basercms · CWE-79 | High8.1 | — | 1.0% | Oct 30, 2020 |
31Monitor | CVE-2020-15159No exploit | Cross Site Scripting leading to RCE in baserCMSbasercms · basercms · CWE-79 | High7.6 | — | 2.2% | Aug 28, 2020 |
30Monitor | CVE-2017-10843No exploit | baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "Fbasercms · basercms | High7.5 | — | 1.4% | Aug 28, 2017 |
- CVE-2017-1084240Plan
SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands
CriticalCVSS 9.8No exploitEPSS 2%basercms · basercmsAug 28, 2017
- CVE-2023-2565439Monitor
baserCMS File Uploader Remote Code Execution (RCE) vulnerability
CriticalCVSS 9.8No exploitEPSS 2%basercms · basercmsMar 23, 2023
- CVE-2023-2565539Monitor
baserCMS allows any file to be uploaded
CriticalCVSS 9.8No exploitEPSS 1%basercms · basercmsMar 23, 2023
- CVE-2023-4379239Monitor
baserCMS Code Injection Vulnerability in Mail Form Feature
CriticalCVSS 9.8No exploitEPSS 1%basercms · basercmsOct 30, 2023
- CVE-2023-4364939Monitor
baserCMS CSRF vulnerability in Content preview Feature
CriticalCVSS 9.8No exploitEPSS 0%basercms · basercmsOct 30, 2023
- CVE-2026-3088037Monitor
baserCMS: OS command injection vulnerability in installer
CriticalCVSS 9.2No exploitEPSS 2%basercms · basercmsMar 30, 2026
- CVE-2021-4124336Monitor
OS Command Injection Vulnerability and Potential Zip Slip Vulnerability
HighCVSS 8.8No exploitEPSS 2%basercms · basercmsNov 26, 2021
- CVE-2021-4127935Monitor
Zip Slip Vulnerability in BaserCMS
HighCVSS 8.8No exploitEPSS 2%basercms · basercmsNov 26, 2021
- CVE-2018-056935Monitor
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbi
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsJun 26, 2018
- CVE-2017-1084435Monitor
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsAug 28, 2017
- CVE-2016-488135Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the aut
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-487835Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-488435Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the aut
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-488235Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-488735Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-488635Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the aut
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-488535Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the aut
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-487635Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2016-487935Monitor
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the aut
HighCVSS 8.8No exploitEPSS 1%basercms · basercmsMay 12, 2017
- CVE-2020-1527634Monitor
Cross Site Scripting in baserCMS
HighCVSS 8.7No exploitEPSS 1%basercms · basercmsOct 30, 2020
- CVE-2018-057232Monitor
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass acces
HighCVSS 8.1No exploitEPSS 2%basercms · basercmsJun 26, 2018
- CVE-2023-5145032Monitor
baserCMS OS command injection vulnerability in Installer
HighCVSS 8.1No exploitEPSS 1%basercms · basercmsFeb 22, 2024
- CVE-2020-1527332Monitor
Cross-Site Scripting in baserCMS
HighCVSS 8.1No exploitEPSS 1%basercms · basercmsOct 30, 2020
- CVE-2020-1515931Monitor
Cross Site Scripting leading to RCE in baserCMS
HighCVSS 7.6No exploitEPSS 2%basercms · basercmsAug 28, 2020
- CVE-2017-1084330Monitor
baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "F
HighCVSS 7.5No exploitEPSS 1%basercms · basercmsAug 28, 2017