Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

baserCMS — Vulnerabilities & Security Advisories 53

All 53 CVE vulnerabilities found in baserCMS, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known Common Weakness Enumeration (CWE) vulnerabilities associated with the baserCMS content management system. It aggregates security issues affecting this specific vendor’s software, focusing on weaknesses such as injection flaws, broken access control, and cross-site scripting. The content collected spans from the initial release of baserCMS through current records, providing a historical perspective on the product's security landscape. Visitors can use this resource to track the vendor’s security advisories and monitor how reported issues are addressed over time. It allows users to understand the prevalence and nature of specific weakness classes within the baserCMS ecosystem, offering insight into common development pitfalls. Additionally, individuals can look up the product’s vulnerability history to assess past risks and understand the evolution of security fixes. This information is crucial for developers, security analysts, and system administrators who need to evaluate the integrity of baserCMS deployments. By reviewing these aggregated data points, stakeholders can make informed decisions regarding patching priorities and mitigation strategies. The page serves as a centralized reference for understanding the specific threat profile of baserCMS, enabling better risk management practices without requiring extensive manual research across disparate sources.

Vendor: baserCMS Users Community

CVE ID Title CVSS Severity Published
CVE-2026-76635 baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php CWE-89 7.2 High 2026-08-20
CVE-2026-65875 basercms 输入验证错误漏洞 CWE-1236 7.1 High 2026-08-03
CVE-2026-32734 baserCMS: Multiple vulnerabilities in baserCMS CWE-79 7.1 High 2026-03-31
CVE-2026-30879 baserCMS: Cross-site scripting vulnerability in blog post CWE-79 6.1AI Medium AI 2026-03-31
CVE-2026-30940 baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE CWE-22 7.2 High 2026-03-31
CVE-2026-30878 baserCMS: Mail Form Acceptance Bypass via Public API CWE-285 5.3 Medium 2026-03-31
CVE-2026-30877 baserCMS: OS Command Injection in the baserCMS Update Functionality CWE-78 9.1 Critical 2026-03-31
CVE-2026-30880 baserCMS: OS command injection vulnerability in installer CWE-78 9.8AI Critical AI 2026-03-31
CVE-2026-27697 baserCMS: SQL injection vulnerability in blog post CWE-89 9.8AI Critical AI 2026-03-31
CVE-2026-21861 baserCMS: OS Command Injection Leading to Remote Code Execution (RCE) CWE-78 9.1 Critical 2026-03-31
CVE-2025-32957 baserCMS: unsafe File Upload Leading to Remote Code Execution (RCE) CWE-434 8.7 High 2026-03-31
CVE-2024-46998 baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature CWE-79 7.1 High 2024-10-24
CVE-2024-46996 baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature CWE-79 6.3 Medium 2024-10-24
CVE-2024-46995 baserCMS has Cross-site Scripting Vulnerability in HTTP 400 Bad Request CWE-79 6.1 Medium 2024-10-24
CVE-2024-46994 baserCMS has Cross-site Scripting Vulnerability in Blog posts and Contents list Feature CWE-79 5.4 Medium 2024-10-24
CVE-2024-26128 baserCMS Cross-site Scripting vulnerability in Content Management CWE-79 5.4 Medium 2024-02-22
CVE-2023-51450 baserCMS OS command injection vulnerability in Installer CWE-78 5.6 Medium 2024-02-22
CVE-2023-44379 baserCMS Cross-site Scripting vulnerability in Site search Feature CWE-79 6.1 Medium 2024-02-22
CVE-2023-43792 baserCMS Code Injection Vulnerability in Mail Form Feature CWE-94 9.8 - 2023-10-30
CVE-2023-43649 baserCMS CSRF vulnerability in Content preview Feature CWE-352 4.7 Medium 2023-10-30
CVE-2023-43648 baserCMS Directory Traversal vulnerability in Form submission data management Feature CWE-22 4.9 Medium 2023-10-30
CVE-2023-43647 baserCMS Cross-site Scripting vulnerability in File upload Feature CWE-79 6.1 Medium 2023-10-30
CVE-2023-29009 basercms XSS Vulnerability via Favorites Feature CWE-79 6.1 Medium 2023-10-27
CVE-2023-25655 baserCMS allows any file to be uploaded CWE-434 9.8 Critical 2023-03-23
CVE-2023-25654 baserCMS File Uploader Remote Code Execution (RCE) vulnerability CWE-434 9.8 Critical 2023-03-23
CVE-2022-41994 baserCMS 跨站脚本漏洞 4.8 - 2022-12-07
CVE-2022-42486 baserCMS 跨站脚本漏洞 4.8 - 2022-12-07
CVE-2022-39325 Cross-site scripting vulnerability in BaserCMS CWE-79 4.6 Medium 2022-11-25
CVE-2021-41279 Zip Slip Vulnerability in BaserCMS CWE-22 7.7 High 2021-11-26
CVE-2021-41243 OS Command Injection Vulnerability and Potential Zip Slip Vulnerability CWE-78 9.1 Critical 2021-11-26

All 53 known CVE vulnerabilities affecting baserCMS with full Chinese analysis, references, and POCs where available.