CVE-2026-93462
- EPSS 0.33%
- Veröffentlicht 30.09.2026 07:42:31
- Zuletzt bearbeitet 01.10.2026 05:17:12
A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information.
CVE-2026-93464
- EPSS 0.14%
- Veröffentlicht 30.09.2026 07:34:33
- Zuletzt bearbeitet 01.10.2026 05:17:12
A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
CVE-2026-93460
- EPSS 0.14%
- Veröffentlicht 30.09.2026 07:34:09
- Zuletzt bearbeitet 01.10.2026 05:17:12
A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
CVE-2026-93463
- EPSS 0.15%
- Veröffentlicht 30.09.2026 07:33:53
- Zuletzt bearbeitet 02.10.2026 01:16:44
A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
CVE-2026-65875
- EPSS 0.15%
- Veröffentlicht 03.08.2026 00:13:39
- Zuletzt bearbeitet 28.08.2026 16:09:10
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.
CVE-2026-32734
- EPSS 0.26%
- Veröffentlicht 31.03.2026 00:46:43
- Zuletzt bearbeitet 01.04.2026 18:56:51
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been patched in version 5.2.3.
CVE-2026-30879
- EPSS 0.23%
- Veröffentlicht 31.03.2026 00:45:50
- Zuletzt bearbeitet 01.04.2026 20:27:36
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.
CVE-2026-30940
- EPSS 1.05%
- Veröffentlicht 31.03.2026 00:45:35
- Zuletzt bearbeitet 01.04.2026 20:26:17
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated admin...
CVE-2026-30878
- EPSS 0.38%
- Veröffentlicht 31.03.2026 00:45:21
- Zuletzt bearbeitet 01.04.2026 20:28:15
baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative con...
CVE-2026-30877
- EPSS 1.52%
- Veröffentlicht 31.03.2026 00:45:09
- Zuletzt bearbeitet 01.04.2026 20:28:43
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary ...