CVE-2020-15276

HIGH

baserCMS <4.4.1 - XSS

Title source: llm
STIX 2.1

Description

baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

References (3)

Core 3

Scores

CVSS v3 7.7
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-79
Status published
Products (2)
basercms/basercms 4.0.0 - 4.4.1
baserproject/basercms 4.4.0 - 4.4.1Packagist
Published Oct 30, 2020
Tracked Since Feb 18, 2026