CVEs we hold for Baserproject
Records whose assigning authority named Baserproject as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-76635baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.phpbaserproject basercms
CVE-2026-30940baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCEbaserproject basercms
CVE-2026-30877baserCMS: OS Command Injection in the baserCMS Update Functionalitybaserproject basercms
CVE-2026-21861baserCMS: OS Command Injection Leading to Remote Code Execution (RCE)baserproject basercms
CVE-2025-32957baserCMS: unsafe File Upload Leading to Remote Code Execution (RCE)baserproject basercms
CVE-2024-46998baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Featurebaserproject basercms
CVE-2024-46996baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Featurebaserproject basercms
CVE-2024-46995baserCMS has Cross-site Scripting Vulnerability in HTTP 400 Bad Requestbaserproject basercms
CVE-2024-46994baserCMS has Cross-site Scripting Vulnerability in Blog posts and Contents list Featurebaserproject basercms
CVE-2024-26128baserCMS Cross-site Scripting vulnerability in Content Managementbaserproject basercms
CVE-2023-44379baserCMS Cross-site Scripting vulnerability in Site search Featurebaserproject basercms
CVE-2023-43648baserCMS Directory Traversal vulnerability in Form submission data management Featurebaserproject basercms
CVE-2023-43647baserCMS Cross-site Scripting vulnerability in File upload Featurebaserproject basercms
CVE-2021-41243OS Command Injection Vulnerability and Potential Zip Slip Vulnerabilitybaserproject basercms
34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.