Vulnerabilities > Basercms > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-11-05 | CVE-2018-18942 | Unrestricted Upload of File with Dangerous Type vulnerability in Basercms In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter. | 7.2 |
2018-06-26 | CVE-2018-0572 | Unspecified vulnerability in Basercms baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via unspecified vectors. | 8.1 |
2018-06-26 | CVE-2018-0569 | OS Command Injection vulnerability in Basercms baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors. | 8.8 |
2017-08-29 | CVE-2017-10844 | Code Injection vulnerability in Basercms baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors. | 8.8 |
2017-08-29 | CVE-2017-10843 | Unspecified vulnerability in Basercms baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form. | 7.5 |
2017-05-12 | CVE-2016-4887 | Cross-Site Request Forgery (CSRF) vulnerability in Basercms 3.0.10 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | 8.8 |
2017-05-12 | CVE-2016-4886 | Cross-Site Request Forgery (CSRF) vulnerability in Basercms 3.0.10 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | 8.8 |
2017-05-12 | CVE-2016-4885 | Cross-Site Request Forgery (CSRF) vulnerability in Basercms 3.0.10 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | 8.8 |
2017-05-12 | CVE-2016-4884 | Cross-Site Request Forgery (CSRF) vulnerability in Basercms 3.0.10 Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | 8.8 |
2017-05-12 | CVE-2016-4882 | Cross-Site Request Forgery (CSRF) vulnerability in Basercms 3.0.10 Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | 8.8 |