Vulnerabilities > Basercms > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-07 CVE-2022-42486 Cross-site Scripting vulnerability in Basercms
Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
network
low complexity
basercms CWE-79
4.8
2022-11-25 CVE-2022-39325 Unspecified vulnerability in Basercms
BaserCMS is a content management system with a japanese language focus.
network
low complexity
basercms
6.1
2021-08-25 CVE-2021-39136 Unspecified vulnerability in Basercms
baserCMS is an open source content management system with a focus on Japanese language support.
network
low complexity
basercms
5.4
2021-03-26 CVE-2021-20683 Cross-site Scripting vulnerability in Basercms
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
network
low complexity
basercms CWE-79
5.4
2021-03-26 CVE-2021-20681 Cross-site Scripting vulnerability in Basercms
Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
network
low complexity
basercms CWE-79
5.4
2018-11-05 CVE-2018-18943 Cross-site Scripting vulnerability in Basercms
An issue was discovered in baserCMS before 4.1.4.
network
low complexity
basercms CWE-79
4.8
2018-06-26 CVE-2018-0575 Information Exposure vulnerability in Basercms
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors.
network
low complexity
basercms CWE-200
5.3
2018-06-26 CVE-2018-0574 Cross-site Scripting vulnerability in Basercms
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
basercms CWE-79
6.1
2018-06-26 CVE-2018-0573 Improper Privilege Management vulnerability in Basercms
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.
network
low complexity
basercms CWE-269
5.3
2018-06-26 CVE-2018-0571 Unrestricted Upload of File with Dangerous Type vulnerability in Basercms
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.
network
low complexity
basercms CWE-434
4.3