Baserproject Basercms vulnerabilities

56 known vulnerabilities affecting baserproject/basercms.

Total CVEs
56
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH22MEDIUM28

Vulnerabilities

Page 1 of 3
CVE-2026-30880CRITICALCVSS 9.2fixed in 5.2.32026-03-31
CVE-2026-30880 [CRITICAL] CWE-78 CVE-2026-30880: baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command inje baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.
ghsanvdosv
CVE-2026-21861HIGHCVSS 7.2fixed in 5.2.32026-03-31
CVE-2026-21861 [HIGH] CWE-78 CVE-2026-21861: baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or
ghsanvdosv
CVE-2026-30940HIGHCVSS 7.2fixed in 5.2.32026-03-31
CVE-2026-30940 [HIGH] CWE-22 CVE-2026-30940: baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory o
ghsanvdosv
CVE-2026-30877HIGHCVSS 7.2fixed in 5.2.32026-03-31
CVE-2026-30877 [HIGH] CWE-78 CVE-2026-30877: baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injectio baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been
ghsanvdosv
CVE-2025-32957HIGHCVSS 7.2fixed in 5.2.32026-03-31
CVE-2025-32957 [HIGH] CWE-434 CVE-2025-32957: baserCMS is a website development framework. Prior to version 5.2.3, the application's restore funct baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using require_once without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and ach
ghsanvdosv
CVE-2026-32734MEDIUMCVSS 6.1fixed in 5.2.32026-03-31
CVE-2026-32734 [MEDIUM] CWE-79 CVE-2026-32734: baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-si baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been patched in version 5.2.3.
ghsanvdosv
CVE-2026-30879MEDIUMCVSS 6.9fixed in 5.2.32026-03-31
CVE-2026-30879 [MEDIUM] CWE-79 CVE-2026-30879: baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scrip baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.
ghsanvdosv
CVE-2026-30878MEDIUMCVSS 5.3fixed in 5.2.32026-03-31
CVE-2026-30878 [MEDIUM] CWE-285 CVE-2026-30878: baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API al baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. This issue has been patched
ghsanvdosv
CVE-2026-27697MEDIUMCVSS 6.9fixed in 5.2.32026-03-31
CVE-2026-27697 [MEDIUM] CWE-89 CVE-2026-27697: baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vu baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been patched in version 5.2.3.
ghsanvdosv
CVE-2024-46996MEDIUMCVSS 5.4fixed in 5.1.22024-10-24
CVE-2024-46996 [MEDIUM] CWE-79 CVE-2024-46996: baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vul baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.
ghsanvdosv
CVE-2024-46994MEDIUMCVSS 5.4fixed in 5.1.22024-10-24
CVE-2024-46994 [MEDIUM] CWE-79 CVE-2024-46994: baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vul baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes this issue.
ghsanvdosv
CVE-2024-46998MEDIUMCVSS 5.4fixed in 5.1.22024-10-24
CVE-2024-46998 [MEDIUM] CWE-79 CVE-2024-46998: baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vul baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the issue.
ghsanvdosv
CVE-2024-46995MEDIUMCVSS 6.1fixed in 5.1.22024-10-24
CVE-2024-46995 [MEDIUM] CWE-79 CVE-2024-46995: baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vul baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.
ghsanvdosv
CVE-2023-51450HIGHCVSS 8.1fixed in 5.0.92024-02-22
CVE-2023-51450 [HIGH] CWE-78 CVE-2023-51450: baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injectio baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.
ghsanvdosv
CVE-2023-44379MEDIUMCVSS 6.1fixed in 5.0.92024-02-22
CVE-2023-44379 [MEDIUM] CWE-79 CVE-2023-44379: baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.
ghsanvdosv
CVE-2024-26128MEDIUMCVSS 5.4fixed in 5.0.92024-02-22
CVE-2024-26128 [MEDIUM] CWE-79 CVE-2024-26128: baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.
ghsanvdosv
CVE-2023-43649CRITICALCVSS 9.8fixed in 4.8.02023-10-30
CVE-2023-43649 [CRITICAL] CWE-352 CVE-2023-43649: baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request f baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.
ghsanvdosv
CVE-2023-43792CRITICALCVSS 9.8v>= 4.6.0, <= 4.7.62023-10-30
CVE-2023-43792 [CRITICAL] CWE-94 CVE-2023-43792: baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Inject baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
ghsanvdosv
CVE-2023-43648MEDIUMCVSS 6.5fixed in 4.8.02023-10-30
CVE-2023-43648 [MEDIUM] CWE-22 CVE-2023-43648: baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
ghsanvdosv
CVE-2023-43647MEDIUMCVSS 5.4fixed in 4.8.02023-10-30
CVE-2023-43647 [MEDIUM] CWE-79 CVE-2023-43647: baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.
ghsanvdosv
Baserproject Basercms vulnerabilities | cvebase