baserCMS Users Community Vulnerabilities and Affected Products
Vulnerabilities associated with baserCMS.
Products
Clear product- baserCMS19 vulnerabilities
- baserCMS plugin Blog3 vulnerabilities
- baserCMS plugin Mail3 vulnerabilities
- baserCMS plugin Feed1 vulnerability
- baserCMS plugin Uploader1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-65875MEDIUM | Generated title:BaserCMS CSV File Injection VulnerabilityBaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed. CWE-1236Aug 3, 2026 | CVSS5.1v4.0 | EPSS0.152% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-42486MEDIUM | baserCMS vulnerable to stored Cross-site ScriptingStored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. CWE-79Dec 7, 2022 | CVSS4.8v3.1 | EPSS0.586% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41994MEDIUM | baserCMS vulnerable to stored Cross-site ScriptingStored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. CWE-79Dec 7, 2022 | CVSS4.8v3.1 | EPSS0.586% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-20683MEDIUM | Cross-site Scripting (XSS) in baserCMSImproper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors. CWE-79Mar 26, 2021 | CVSS5.4v3.1 | EPSS0.731% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-20682HIGH | OS Command Injection in baserCMSbaserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors. CWE-78Mar 26, 2021 | CVSS7.2v3.1 | EPSS2.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-20681MEDIUM | Cross-site Scripting (XSS) in baserCMSImproper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors. CWE-79Mar 26, 2021 | CVSS5.4v3.1 | EPSS0.731% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0571MEDIUM | baserCMS arbitrary file upload vulnerabilitybaserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files. CWE-434Jun 26, 2018 | CVSS4.3v3.0 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0570MEDIUM | XSS in baserCMSCross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79Jun 26, 2018 | CVSS5.4v3.0 | EPSS0.677% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0574MEDIUM | XSS in baserCMSCross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79Jun 26, 2018 | CVSS6.1v3.0 | EPSS0.842% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0573MEDIUM | baserCMS Access Control BypassbaserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors. CWE-269Jun 26, 2018 | CVSS5.3v3.0 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0575MEDIUM | Sensitive Data Exposure in baserCMSbaserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors. CWE-200Jun 26, 2018 | CVSS5.3v3.0 | EPSS1.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0569HIGH | OS Command Injection in baserCMSbaserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors. CWE-78Jun 26, 2018 | CVSS8.8v3.0 | EPSS1.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0572HIGH | baserCMS vulnerable to Access Control BypassbaserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via unspecified vectors. Jun 26, 2018 | CVSS8.1v3.0 | EPSS1.63% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-10842CRITICAL | baserCMS SQL Injection vulnerabilitySQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. CWE-89Aug 28, 2017 | CVSS9.8v3.0 | EPSS1.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-10843HIGH | Arbitrary file delete in baserCMSbaserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form. Aug 28, 2017 | CVSS7.5v3.0 | EPSS1.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4882HIGH | Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. CWE-352May 12, 2017 | CVSS8.8v3.0 | EPSS0.924% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4878HIGH | baserCMS Cross Site Request Forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. CWE-352May 12, 2017 | CVSS8.8v3.0 | EPSS0.944% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4876HIGH | Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators to execute arbitrary PHP code via unspecified vectors. CWE-352May 12, 2017 | CVSS8.8v3.0 | EPSS0.913% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4883MEDIUM | Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79May 12, 2017 | CVSS5.4v3.0 | EPSS0.902% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |