basercms CVE Vulnerabilities & Metrics

Focus on basercms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About basercms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with basercms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total basercms CVEs: 56
Earliest CVE date: 02 Oct 2011, 02:53 UTC
Latest CVE date: 24 Oct 2024, 19:15 UTC

Latest CVE reference: CVE-2024-46998

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 4

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -60.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -60.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical basercms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.89

Max CVSS: 9.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 29
4.0-6.9 26
7.0-8.9 1
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS basercms CVEs

These are the five CVEs with the highest CVSS scores for basercms, sorted by severity first and recency.

All CVEs for basercms

CVE-2024-46998 basercms vulnerability CVSS: 0 24 Oct 2024, 19:15 UTC

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the issue.

CVE-2024-46996 basercms vulnerability CVSS: 0 24 Oct 2024, 19:15 UTC

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.

CVE-2024-46995 basercms vulnerability CVSS: 0 24 Oct 2024, 19:15 UTC

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.

CVE-2024-46994 basercms vulnerability CVSS: 0 24 Oct 2024, 19:15 UTC

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes this issue.

CVE-2024-26128 basercms vulnerability CVSS: 0 22 Feb 2024, 19:15 UTC

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.

CVE-2023-51450 basercms vulnerability CVSS: 0 22 Feb 2024, 15:15 UTC

baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.

CVE-2023-44379 basercms vulnerability CVSS: 0 22 Feb 2024, 15:15 UTC

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.

CVE-2023-43792 basercms vulnerability CVSS: 0 30 Oct 2023, 21:15 UTC

baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.

CVE-2023-43649 basercms vulnerability CVSS: 0 30 Oct 2023, 19:15 UTC

baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.

CVE-2023-43648 basercms vulnerability CVSS: 0 30 Oct 2023, 19:15 UTC

baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.

CVE-2023-43647 basercms vulnerability CVSS: 0 30 Oct 2023, 19:15 UTC

baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.

CVE-2023-29009 basercms vulnerability CVSS: 0 27 Oct 2023, 20:15 UTC

baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.

CVE-2023-25655 basercms vulnerability CVSS: 0 23 Mar 2023, 20:15 UTC

baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.

CVE-2023-25654 basercms vulnerability CVSS: 0 23 Mar 2023, 20:15 UTC

baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.

CVE-2022-42486 basercms vulnerability CVSS: 0 07 Dec 2022, 04:15 UTC

Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

CVE-2022-41994 basercms vulnerability CVSS: 0 07 Dec 2022, 04:15 UTC

Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

CVE-2022-39325 basercms vulnerability CVSS: 0 25 Nov 2022, 20:15 UTC

BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability.

CVE-2021-41279 basercms vulnerability CVSS: 9.0 26 Nov 2021, 18:15 UTC

BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted zip files capable of path traversal on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.

CVE-2021-41243 basercms vulnerability CVSS: 9.0 26 Nov 2021, 18:15 UTC

There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.

CVE-2021-39136 basercms vulnerability CVSS: 3.5 25 Aug 2021, 18:15 UTC

baserCMS is an open source content management system with a focus on Japanese language support. In affected versions there is a cross-site scripting vulnerability in the file upload function of the management system of baserCMS. Users are advised to update as soon as possible. No workaround are available to mitigate this issue.

CVE-2021-20683 basercms vulnerability CVSS: 3.5 26 Mar 2021, 09:15 UTC

Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

CVE-2021-20682 basercms vulnerability CVSS: 9.0 26 Mar 2021, 09:15 UTC

baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

CVE-2021-20681 basercms vulnerability CVSS: 3.5 26 Mar 2021, 09:15 UTC

Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.

CVE-2020-15276 basercms vulnerability CVSS: 3.5 30 Oct 2020, 19:15 UTC

baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

CVE-2020-15273 basercms vulnerability CVSS: 3.5 30 Oct 2020, 19:15 UTC

baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be executed by entering specific characters in the account that can access the file upload function category list, subsite setting list, widget area edit, and feed list on the management screen. The issue was introduced in version 4.0.0. It is fixed in version 4.4.1.

CVE-2020-15277 basercms vulnerability CVSS: 6.5 30 Oct 2020, 18:15 UTC

baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.

CVE-2020-15159 basercms vulnerability CVSS: 4.6 28 Aug 2020, 22:15 UTC

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and UploaderFilesController.php. This is fixed in version 4.3.7.

CVE-2020-15155 basercms vulnerability CVSS: 2.1 28 Aug 2020, 22:15 UTC

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

CVE-2020-15154 basercms vulnerability CVSS: 2.1 28 Aug 2020, 21:15 UTC

baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php, index_list_tree.php, jquery.bcTree.js. The issue is fixed in version 4.3.7.

CVE-2018-18943 basercms vulnerability CVSS: 3.5 05 Nov 2018, 09:29 UTC

An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.

CVE-2018-18942 basercms vulnerability CVSS: 6.5 05 Nov 2018, 09:29 UTC

In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.

CVE-2018-0575 basercms vulnerability CVSS: 5.0 26 Jun 2018, 14:29 UTC

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors.

CVE-2018-0574 basercms vulnerability CVSS: 4.3 26 Jun 2018, 14:29 UTC

Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2018-0573 basercms vulnerability CVSS: 5.0 26 Jun 2018, 14:29 UTC

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.

CVE-2018-0572 basercms vulnerability CVSS: 5.5 26 Jun 2018, 14:29 UTC

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via unspecified vectors.

CVE-2018-0571 basercms vulnerability CVSS: 4.0 26 Jun 2018, 14:29 UTC

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.

CVE-2018-0570 basercms vulnerability CVSS: 3.5 26 Jun 2018, 14:29 UTC

Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2018-0569 basercms vulnerability CVSS: 6.5 26 Jun 2018, 14:29 UTC

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2017-10844 basercms vulnerability CVSS: 6.5 29 Aug 2017, 01:35 UTC

baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.

CVE-2017-10843 basercms vulnerability CVSS: 6.4 29 Aug 2017, 01:35 UTC

baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.

CVE-2017-10842 basercms vulnerability CVSS: 7.5 29 Aug 2017, 01:35 UTC

SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2016-4887 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4886 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4885 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4884 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4883 basercms vulnerability CVSS: 3.5 12 May 2017, 18:29 UTC

Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2016-4882 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4881 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4880 basercms vulnerability CVSS: 3.5 12 May 2017, 18:29 UTC

Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2016-4879 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4878 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-4877 basercms vulnerability CVSS: 3.5 12 May 2017, 18:29 UTC

Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2016-4876 basercms vulnerability CVSS: 6.8 12 May 2017, 18:29 UTC

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators to execute arbitrary PHP code via unspecified vectors.

CVE-2015-7769 basercms vulnerability CVSS: 6.5 19 Feb 2016, 19:59 UTC

baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

CVE-2015-5641 basercms vulnerability CVSS: 6.5 06 Oct 2015, 01:59 UTC

SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVE-2015-5640 basercms vulnerability CVSS: 6.5 06 Oct 2015, 01:59 UTC

baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.

CVE-2012-1248 basercms vulnerability CVSS: 5.1 15 May 2012, 20:55 UTC

app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.

CVE-2011-2674 basercms vulnerability CVSS: 4.9 02 Oct 2011, 02:53 UTC

BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.

CVE-2011-2673 basercms vulnerability CVSS: 4.3 02 Oct 2011, 02:53 UTC

Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.