Basercms-users-community
21 CVEs tracked since 2017. Since May 2017, none of them reached CISA KEV.
Basercms-users-community CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-05 | 12 | 0 |
| 2017-06 | null or fewer | |
| 2017-07 | null or fewer | |
| 2017-08 | 2 | 0 |
| 2017-09 | null or fewer | |
| 2017-10 | null or fewer | |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | null or fewer | |
| 2018-02 | null or fewer | |
| 2018-03 | null or fewer | |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | 7 | 0 |
Products
The products that kept showing up in Basercms-users-community's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Basercms-users-community.
- CVE-2026-65875BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious ...7.1
- CVE-2022-42486Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary...4.8
- CVE-2022-41994Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary s...4.8
- CVE-2021-20683Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecif...5.4
- CVE-2021-20682baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.7.2
- CVE-2021-20681Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vect...5.4
- CVE-2018-0575baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site u...5.3
- CVE-2018-0572baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via u...8.1
- CVE-2018-0571baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.4.3
- CVE-2018-0570Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or ...5.4
- CVE-2018-0574Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspe...6.1
- CVE-2018-0573baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site ...5.3
- CVE-2018-0569baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors.8.8
- CVE-2017-10843baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.7.5
- CVE-2017-10842SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.9.8
The record
- Peak rank
- #29 in May 2017
- Busiest month shown
- May 2017, 12 CVEs
- Months with a KEV entry
- 0 since May 2017
- Monthly snapshots
- 3 since 2017