Vulnerabilities > Basercms > Low

DATE CVE VULNERABILITY TITLE RISK
2021-08-25 CVE-2021-39136 Cross-site Scripting vulnerability in Basercms
baserCMS is an open source content management system with a focus on Japanese language support.
network
basercms CWE-79
3.5
2021-03-26 CVE-2021-20681 Cross-site Scripting vulnerability in Basercms
Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
network
basercms CWE-79
3.5
2021-03-26 CVE-2021-20683 Cross-site Scripting vulnerability in Basercms
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
network
basercms CWE-79
3.5
2020-10-30 CVE-2020-15273 Cross-site Scripting vulnerability in Basercms
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting.
network
basercms CWE-79
3.5
2020-10-30 CVE-2020-15276 Cross-site Scripting vulnerability in Basercms
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting.
network
basercms CWE-79
3.5
2020-08-28 CVE-2020-15155 Cross-site Scripting vulnerability in Basercms
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution.
network
high complexity
basercms CWE-79
2.1
2020-08-28 CVE-2020-15154 Cross-site Scripting vulnerability in Basercms
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution.
network
high complexity
basercms CWE-79
2.1
2018-11-05 CVE-2018-18943 Cross-site Scripting vulnerability in Basercms
An issue was discovered in baserCMS before 4.1.4.
network
basercms CWE-79
3.5
2018-06-26 CVE-2018-0570 Cross-site Scripting vulnerability in Basercms
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
network
basercms CWE-79
3.5
2017-05-12 CVE-2016-4877 Cross-site Scripting vulnerability in Basercms and Mail
Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
network
basercms CWE-79
3.5