Search Results (6 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97150 1 Basercms Users Community 1 Bcaddonmigrator 2026-09-30 N/A
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
CVE-2026-93464 1 Basercms Users Community 1 Basercms 2026-09-30 N/A
Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
CVE-2026-93463 1 Basercms Users Community 1 Basercms 2026-09-30 N/A
Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
CVE-2026-93460 1 Basercms Users Community 1 Basercms 2026-09-30 N/A
Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
CVE-2026-93462 1 Basercms Users Community 1 Basercms 2026-09-30 N/A
Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained.
CVE-2026-65875 1 Basercms Users Community 1 Basercms 2026-08-03 7.1 High
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.