baserproject/basercms Security Advisories for 3.0.21 (24)
- 
                        [MEDIUM] baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings FeaturePKSA-vwf1-pc89-hwmm CVE-2024-46998 GHSA-p3m2-mj3j-j49x Affected version: <=5.1.1 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts FeaturePKSA-2n26-3nmt-wj9x CVE-2024-46996 GHSA-66jv-qrm3-vvfg Affected version: <=5.1.1 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad RequestPKSA-p655-dyj9-4mvs CVE-2024-46995 GHSA-mr7q-fv7j-jcgv Affected version: <=5.1.1 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list FeaturePKSA-xcdb-2rf5-69bx CVE-2024-46994 GHSA-wrjc-fmfq-w3jr Affected version: <=5.1.1 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS Cross-site Scripting vulnerability in Site search FeaturePKSA-mwdp-p7zx-ctg9 CVE-2023-44379 GHSA-66c2-p8rh-qx87 Affected version: <5.0.9 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS OS command injection vulnerability in InstallerPKSA-8rh3-g94s-b7nm CVE-2023-51450 GHSA-77fc-4cv5-hmfr Affected version: <5.0.9 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS Cross-site Scripting vulnerability in Content ManagementPKSA-6q5n-gkcc-h3dr CVE-2024-26128 GHSA-jjxq-m8h3-4vw5 Affected version: <5.0.9 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS CSRF vulnerability in Content preview FeaturePKSA-nxwy-9p2v-qc9n CVE-2023-43649 GHSA-fw9x-cqjq-7jx5 Affected version: <4.8.0 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS Directory Traversal vulnerability in Form submission data management FeaturePKSA-22d5-943w-6dy7 CVE-2023-43648 GHSA-hmqj-gv2m-hq55 Affected version: <4.8.0 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS Cross-site Scripting vulnerability in File upload FeaturePKSA-bxhm-kd8v-fz1m CVE-2023-43647 GHSA-ggj4-78rm-6xgv Affected version: <4.8.0 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS Cross-site Scripting Vulnerability in Favorites FeaturePKSA-fcwx-h4gs-44bz CVE-2023-29009 GHSA-8vqx-prq4-rqrq Affected version: <4.8.0 Reported by: 
 GitHub
- 
                        [CRITICAL] baserCMS allows any file to be uploadedPKSA-986w-k86s-1jm5 CVE-2023-25655 GHSA-mfvg-qwcw-qvc8 Affected version: <4.7.5 Reported by: 
 GitHub
- 
                        [CRITICAL] baserCMS File Uploader Remote Code Execution (RCE) vulnerabilityPKSA-by4q-b96z-rq2t CVE-2023-25654 GHSA-h4cc-fxpp-pgw9 Affected version: <4.7.5 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS vulnerable to stored Cross-site ScriptingPKSA-6fzq-jkcg-kvtm CVE-2022-42486 GHSA-7w2v-35j3-xrm9 Affected version: <4.7.2 Reported by: 
 GitHub
- 
                        [MEDIUM] baserCMS vulnerable to stored Cross-site ScriptingPKSA-rfzx-7pgr-3782 CVE-2022-41994 GHSA-vxwf-79ch-f7f7 Affected version: <4.7.2 Reported by: 
 GitHub
- 
                        [MEDIUM] baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerabilityPKSA-bbz7-vqbc-jf2x CVE-2022-39325 GHSA-395x-wv32-44v5 Affected version: <=4.7.1 Reported by: 
 GitHub
- 
                        [MEDIUM] XSS in baserCMS before 4.1.4PKSA-576q-v6sb-s2wt CVE-2018-18943 GHSA-fx2m-5m9v-jhgp Affected version: <4.1.4 Reported by: 
 GitHub
- 
                        [HIGH] RCE in baserCMS before 4.1.4PKSA-zrgf-b4wd-25sd CVE-2018-18942 GHSA-rjc2-x53r-6c9r Affected version: <4.1.4 Reported by: 
 GitHub
- 
                        [CRITICAL] OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMSPKSA-8sn2-zvy7-x3wh CVE-2021-41243 GHSA-7rpc-9m88-cf9w Affected version: <4.5.4 Reported by: 
 GitHub
- 
                        [HIGH] Potential Zip Slip Vulnerability in baserCMSPKSA-1pv2-4z3b-ffqj CVE-2021-41279 GHSA-4x2f-54wr-4hjg Affected version: <4.5.4 Reported by: 
 GitHub
- 
                        [HIGH] Cross-site scripting vulnerability in file uploadPKSA-wns2-ncyt-ck6c CVE-2021-39136 GHSA-hgjr-632x-qpp3 Affected version: <=4.5.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting (XSS) in baserCMSPKSA-fnvn-dwyj-npvb CVE-2021-20683 GHSA-v9w8-hq92-v39m Affected version: <4.4.5 Reported by: 
 GitHub
- 
                        [HIGH] OS Command Injection in baserCMSPKSA-q92h-r6kb-v79s CVE-2021-20682 GHSA-g39q-f4rm-85x4 Affected version: <4.4.5 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting (XSS) in baserCMSPKSA-gs8f-m49s-36b8 CVE-2021-20681 GHSA-24p5-x9f9-vvpx Affected version: <4.4.5 Reported by: 
 GitHub