CVE-2023-44379
- EPSS 0.47%
- Veröffentlicht 22.02.2024 15:15:08
- Zuletzt bearbeitet 18.12.2024 16:54:13
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.
CVE-2023-43792
- EPSS 0.57%
- Veröffentlicht 30.10.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 08:24:47
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
CVE-2023-43649
- EPSS 0.35%
- Veröffentlicht 30.10.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:32
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.
CVE-2023-43648
- EPSS 0.97%
- Veröffentlicht 30.10.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:32
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
CVE-2023-43647
- EPSS 0.51%
- Veröffentlicht 30.10.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:32
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.
CVE-2023-29009
- EPSS 0.47%
- Veröffentlicht 27.10.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:56:23
baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.
CVE-2023-25655
- EPSS 1.09%
- Veröffentlicht 23.03.2023 20:15:15
- Zuletzt bearbeitet 21.11.2024 07:49:52
baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.
CVE-2023-25654
- EPSS 1.53%
- Veröffentlicht 23.03.2023 20:15:14
- Zuletzt bearbeitet 21.11.2024 07:49:52
baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.
CVE-2022-42486
- EPSS 0.59%
- Veröffentlicht 07.12.2022 04:15:10
- Zuletzt bearbeitet 23.04.2025 16:15:26
Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
CVE-2022-41994
- EPSS 0.59%
- Veröffentlicht 07.12.2022 04:15:10
- Zuletzt bearbeitet 23.04.2025 15:15:51
Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.