Basercms

Basercms

69 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 03.08.2026 00:13:39
  • Zuletzt bearbeitet 03.08.2026 16:16:30

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.

  • EPSS 0.26%
  • Veröffentlicht 31.03.2026 00:46:43
  • Zuletzt bearbeitet 01.04.2026 18:56:51

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been patched in version 5.2.3.

  • EPSS 0.23%
  • Veröffentlicht 31.03.2026 00:45:50
  • Zuletzt bearbeitet 01.04.2026 20:27:36

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.

Exploit
  • EPSS 1.05%
  • Veröffentlicht 31.03.2026 00:45:35
  • Zuletzt bearbeitet 01.04.2026 20:26:17

baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated admin...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 31.03.2026 00:45:21
  • Zuletzt bearbeitet 01.04.2026 20:28:15

baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative con...

  • EPSS 1.52%
  • Veröffentlicht 31.03.2026 00:45:09
  • Zuletzt bearbeitet 01.04.2026 20:28:43

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary ...

  • EPSS 2.03%
  • Veröffentlicht 31.03.2026 00:44:39
  • Zuletzt bearbeitet 01.04.2026 20:27:00

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.

  • EPSS 0.41%
  • Veröffentlicht 31.03.2026 00:44:20
  • Zuletzt bearbeitet 01.04.2026 20:29:10

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been patched in version 5.2.3.

Exploit
  • EPSS 2.28%
  • Veröffentlicht 31.03.2026 00:43:58
  • Zuletzt bearbeitet 01.04.2026 20:29:39

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to impro...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 31.03.2026 00:43:48
  • Zuletzt bearbeitet 01.04.2026 20:31:57

baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using require_once without va...