baserproject/basercms
Packagist47 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting baserproject/basercmspage 1 of 1
- CVE-2011-2674NONECVSS 0.0EG 0.0✓ Fixed in 1.6.122011-10-02
BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.
- CVE-2015-5640NONECVSS 0.0EG 0.0✓ Fixed in 3.0.82015-10-06
vulnerable: 2.0.0-rc1 ... 3.0.7.1 (8 versions)
baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.
- CVE-2016-4878HIGHCVSS 8.8EG 8.8✓ Fixed in 3.0.112017-05-12
vulnerable: 0.0.1 ... 3.0.9 (26 versions)
Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- CVE-2016-4879HIGHCVSS 8.8EG 8.82017-05-12
vulnerable: 0.0.1 ... 3.0.9 (26 versions)
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- CVE-2016-4880MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.0.112017-05-12
vulnerable: 0.0.1 ... 3.0.9 (26 versions)
Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2016-4881HIGHCVSS 8.8EG 8.8✓ Fixed in 3.0.112017-05-12
vulnerable: 0.0.1 ... 3.0.9 (26 versions)
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- CVE-2017-10842CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.0.62017-08-29
vulnerable: 4.0.0
SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2017-10843HIGHCVSS 7.5EG 7.5✓ Fixed in 4.0.62017-08-29
vulnerable: 4.0.0 ... 4.0.5.2 (9 versions)
baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.
- CVE-2017-10844HIGHCVSS 8.8EG 8.82017-08-29
vulnerable: 4.0.0
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
- CVE-2018-0569HIGHCVSS 8.8EG 8.82018-06-26
vulnerable: 0.0.1 ... 3.0.9 (31 versions)
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0570MEDIUMCVSS 5.4EG 5.42018-06-26
vulnerable: 0.0.1 ... 3.0.9 (31 versions)
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2018-0571MEDIUMCVSS 4.3EG 4.3✓ Fixed in 3.0.162018-06-26
vulnerable: 0.0.1 ... 3.0.9 (31 versions)
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.
- CVE-2018-0572HIGHCVSS 8.1EG 8.1✓ Fixed in 3.0.162018-06-26
vulnerable: 2.0.0-rc1 ... 3.0.9.1 (20 versions)
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via unspecified vectors.
- CVE-2018-0573MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.1.12018-06-26
vulnerable: 4.0.0, 4.1.0
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.
- CVE-2018-0574MEDIUMCVSS 6.1EG 6.12018-06-26
vulnerable: 0.0.1 ... 3.0.9 (31 versions)
Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2018-0575MEDIUMCVSS 5.3EG 5.32018-06-26
vulnerable: 0.0.1 ... 3.0.9 (31 versions)
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors.
- CVE-2018-18942HIGHCVSS 7.2EG 7.2✓ Fixed in 4.1.42018-11-05
vulnerable: 0.0.1 ... 4.1.0 (44 versions)
In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
- CVE-2018-18943MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.1.42018-11-05
vulnerable: 0.0.1 ... 4.1.0 (44 versions)
An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit U…
- CVE-2020-15154HIGHCVSS 7.3EG 7.3✓ Fixed in 4.3.72020-08-28
vulnerable: 4.0.0 ... 4.3.6 (39 versions)
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options…
- CVE-2020-15155HIGHCVSS 7.3EG 7.3✓ Fixed in 4.3.72020-08-28
vulnerable: 4.0.0 ... 4.3.6 (39 versions)
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.
- CVE-2020-15159HIGHCVSS 7.6EG 7.6✓ Fixed in 4.3.72020-08-28
vulnerable: 4.0.0 ... 4.3.6 (39 versions)
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected comp…
- CVE-2020-15273HIGHCVSS 7.3EG 7.3✓ Fixed in 4.4.12020-10-30
vulnerable: 4.4.0
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be execut…
- CVE-2020-15276HIGHCVSS 7.7EG 7.7✓ Fixed in 4.4.12020-10-30
vulnerable: 4.4.0
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
- CVE-2020-15277HIGHCVSS 7.2EG 7.2✓ Fixed in 4.4.12020-10-30
vulnerable: 4.4.0
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. T…
- CVE-2021-20681MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.4.52021-03-26
vulnerable: 0.0.1 ... 4.2.5 (50 versions)
Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
- CVE-2021-20682HIGHCVSS 7.2EG 7.2✓ Fixed in 4.4.52021-03-26
vulnerable: 0.0.1 ... 4.2.5 (50 versions)
baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.
- CVE-2021-20683MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.4.52021-03-26
vulnerable: 0.0.1 ... 4.2.5 (50 versions)
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
- CVE-2021-39136HIGHCVSS 8.7EG 8.7✓ Fixed in 4.5.12021-08-25
vulnerable: 2.0.0-rc1 ... 4.5.0 (85 versions)
baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are …
- CVE-2021-41243CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.5.42021-11-26
vulnerable: 2.0.0-rc1 ... 4.5.3 (88 versions)
There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host o…
- CVE-2021-41279HIGHCVSS 7.7EG 7.7✓ Fixed in 4.5.42021-11-26
vulnerable: 2.0.0-rc1 ... 4.5.3 (88 versions)
BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted zip files capable of path traversal on the host operating system. This is a…
- CVE-2022-39325MEDIUMCVSS 4.6EG 4.6✓ Fixed in 4.7.22022-11-25
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the ma…
- CVE-2022-41994MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.7.22022-12-07
Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
- CVE-2022-42486MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.7.22022-12-07
Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
- CVE-2023-25654CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.7.52023-03-23
baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.
- CVE-2023-25655CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.7.52023-03-23
baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.
- CVE-2023-29009MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.8.02023-10-27
vulnerable: 0.0.1 ... 4.5.4 (52 versions)
baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.
- CVE-2023-43647MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.8.02023-10-30
vulnerable: 0.0.1 ... 4.2.5 (50 versions)
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.
- CVE-2023-43648MEDIUMCVSS 4.9EG 4.9✓ Fixed in 4.8.02023-10-30
vulnerable: 0.0.1 ... 4.2.5 (50 versions)
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.
- CVE-2023-43649MEDIUMCVSS 4.7EG 4.7✓ Fixed in 4.8.02023-10-30
vulnerable: 0.0.1 ... 4.2.5 (50 versions)
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.
- CVE-2023-43792CRITICALCVSS 9.8EG 5.32023-10-30
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
- CVE-2023-44379MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.0.92024-02-22
vulnerable: 2.0.0-rc1 ... 5.0.8 (119 versions)
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.
- CVE-2023-51450MEDIUMCVSS 5.6EG 5.6✓ Fixed in 5.0.92024-02-22
vulnerable: 0.0.1 ... 5.0.8 (65 versions)
baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.
- CVE-2024-26128MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.0.92024-02-22
vulnerable: 0.0.1 ... 5.0.8 (65 versions)
baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.
- CVE-2024-46994MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.1.22024-10-24
vulnerable: 2.0.0-rc1 ... 5.1.1 (133 versions)
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes this issue.
- CVE-2024-46995MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.1.22024-10-24
vulnerable: 2.0.0-rc1 ... 5.1.1 (133 versions)
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.
- CVE-2024-46996MEDIUMCVSS 6.3EG 6.3✓ Fixed in 5.1.22024-10-24
vulnerable: 2.0.0-rc1 ... 5.1.1 (133 versions)
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.
- CVE-2024-46998HIGHCVSS 7.1EG 7.1✓ Fixed in 5.1.22024-10-24
vulnerable: 2.0.0-rc1 ... 5.1.1 (133 versions)
baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the issue.
Check whether baserproject/basercms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for baserproject/basercms CVEs against the assets you own.
Start Free Scan →