Vulnerabilities > Basercms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-10-30 | CVE-2020-15276 | Cross-site Scripting vulnerability in Basercms baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. | 8.7 |
2020-10-30 | CVE-2020-15273 | Cross-site Scripting vulnerability in Basercms baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. | 8.1 |
2020-10-30 | CVE-2020-15277 | Unrestricted Upload of File with Dangerous Type vulnerability in Basercms baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). | 7.2 |
2020-08-28 | CVE-2020-15159 | Cross-site Scripting vulnerability in Basercms baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). | 7.6 |
2020-08-28 | CVE-2020-15155 | Cross-site Scripting vulnerability in Basercms baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. | 7.3 |
2020-08-28 | CVE-2020-15154 | Cross-site Scripting vulnerability in Basercms baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. | 7.3 |
2018-11-05 | CVE-2018-18943 | Cross-site Scripting vulnerability in Basercms An issue was discovered in baserCMS before 4.1.4. | 4.8 |
2018-11-05 | CVE-2018-18942 | Unrestricted Upload of File with Dangerous Type vulnerability in Basercms In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter. | 7.2 |
2018-06-26 | CVE-2018-0575 | Information Exposure vulnerability in Basercms baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors. | 5.3 |
2018-06-26 | CVE-2018-0574 | Cross-site Scripting vulnerability in Basercms Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |