Basercms
70 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Basercms, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Basercms CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 4 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 9 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 70 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical9
- High29
- Medium32
Latest CVEs
The 15 most recently published vulnerabilities affecting Basercms.
- CVE-2026-76635baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php7.2
- CVE-2026-65875BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious ...7.1
- CVE-2026-32734baserCMS: Multiple vulnerabilities in baserCMS7.1
- CVE-2026-30879baserCMS: Cross-site scripting vulnerability in blog post6.1
- CVE-2026-30940baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE7.2
- CVE-2026-30878baserCMS: Mail Form Acceptance Bypass via Public API5.3
- CVE-2026-30877baserCMS: OS Command Injection in the baserCMS Update Functionality9.1
- CVE-2026-30880baserCMS: OS command injection vulnerability in installer9.8
- CVE-2026-27697baserCMS: SQL injection vulnerability in blog post9.8
- CVE-2026-21861baserCMS: OS Command Injection Leading to Remote Code Execution (RCE)9.1
- CVE-2025-32957baserCMS: unsafe File Upload Leading to Remote Code Execution (RCE)8.7
- CVE-2024-46998baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature7.1
- CVE-2024-46996baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature6.3
- CVE-2024-46995baserCMS has Cross-site Scripting Vulnerability in HTTP 400 Bad Request6.1
- CVE-2024-46994baserCMS has Cross-site Scripting Vulnerability in Blog posts and Contents list Feature5.4
Product grouping is registry-driven, with AI assist and human review. How it works