Skip to main content

Vendor archive

basercms CVEs

Beta · best-effort

68 CVEs tagged to vendor basercms8 Critical, 27 High, 33 Medium, 0 Low, 0 Unrated.

CVE-2016-4887

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4886

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4885

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4884

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4883

Published May 12, 2017

Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4882

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vecto…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4881

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4880

Published May 12, 2017

Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4879

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4878

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vecto…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4877

Published May 12, 2017

Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4876

Published May 12, 2017

Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators to execute arbitrary…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7769

Published Feb 19, 2016

baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5641

Published Oct 6, 2015

SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5640

Published Oct 6, 2015

baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1248

Published May 15, 2012

app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by lever…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2674

Published Oct 2, 2011

BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified ve…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2673

Published Oct 2, 2011

Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-68 of 68 CVEsPage 3 of 3