Basercms

Basercms

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.68%
  • Veröffentlicht 26.06.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:30

Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 1.5%
  • Veröffentlicht 26.06.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:29

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors.

  • EPSS 1.77%
  • Veröffentlicht 29.08.2017 01:35:13
  • Zuletzt bearbeitet 13.05.2026 00:24:29

SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • EPSS 1.42%
  • Veröffentlicht 29.08.2017 01:35:13
  • Zuletzt bearbeitet 13.05.2026 00:24:29

baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.

  • EPSS 1.47%
  • Veröffentlicht 29.08.2017 01:35:13
  • Zuletzt bearbeitet 13.05.2026 00:24:29

baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.

  • EPSS 0.92%
  • Veröffentlicht 12.05.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.91%
  • Veröffentlicht 12.05.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators to execute arbitrary PHP code via unspecified vectors.

  • EPSS 0.9%
  • Veröffentlicht 12.05.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.94%
  • Veröffentlicht 12.05.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • EPSS 0.88%
  • Veröffentlicht 12.05.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.