Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BaserCMS — Vulnerabilities & Security Advisories 52

All 52 CVE vulnerabilities found in BaserCMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common vulnerability data for baserCMS, a popular open-source content management system, specifically focusing on weakness types and associated tags. It collects information regarding security flaws affecting various versions of the software, covering historical records and recent findings to ensure comprehensive visibility into the product's security posture over time. Readers can utilize this resource to track vendor advisories as they are issued, gain a deeper understanding of specific weakness classes such as input validation or cross-site scripting issues, and look up the complete vulnerability history for baserCMS to assess risks associated with different release cycles. By consolidating these details, the page serves as a centralized hub for security researchers, system administrators, and developers who need to evaluate the integrity of their deployments. The information is structured to facilitate efficient analysis of past incidents and current threats, allowing users to identify patterns in how vulnerabilities are exploited or remediated within the baserCMS ecosystem. This approach helps stakeholders make informed decisions regarding patching strategies and security configurations without needing to scour multiple disparate sources. The content is regularly updated to reflect the latest disclosures and maintain accuracy regarding the software's evolving security landscape.

Vendor: baserCMS Users Community

CVE IDTitleCVSSSeverityPublished
CVE-2026-65875 basercms 输入验证错误漏洞 CWE-1236 7.1 High2026-08-03
CVE-2026-32734 baserCMS: Multiple vulnerabilities in baserCMS CWE-79 7.1 High2026-03-31
CVE-2026-30879 baserCMS: Cross-site scripting vulnerability in blog post CWE-79 6.1AIMediumAI2026-03-31
CVE-2026-30940 baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE CWE-22 7.2 High2026-03-31
CVE-2026-30878 baserCMS: Mail Form Acceptance Bypass via Public API CWE-285 5.3 Medium2026-03-31
CVE-2026-30877 baserCMS: OS Command Injection in the baserCMS Update Functionality CWE-78 9.1 Critical2026-03-31
CVE-2026-30880 baserCMS: OS command injection vulnerability in installer CWE-78 9.8AICriticalAI2026-03-31
CVE-2026-27697 baserCMS: SQL injection vulnerability in blog post CWE-89 9.8AICriticalAI2026-03-31
CVE-2026-21861 baserCMS: OS Command Injection Leading to Remote Code Execution (RCE) CWE-78 9.1 Critical2026-03-31
CVE-2025-32957 baserCMS: unsafe File Upload Leading to Remote Code Execution (RCE) CWE-434 8.7 High2026-03-31
CVE-2024-46998 baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature CWE-79 7.1 High2024-10-24
CVE-2024-46996 baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature CWE-79 6.3 Medium2024-10-24
CVE-2024-46995 baserCMS has Cross-site Scripting Vulnerability in HTTP 400 Bad Request CWE-79 6.1 Medium2024-10-24
CVE-2024-46994 baserCMS has Cross-site Scripting Vulnerability in Blog posts and Contents list Feature CWE-79 5.4 Medium2024-10-24
CVE-2024-26128 baserCMS Cross-site Scripting vulnerability in Content Management CWE-79 5.4 Medium2024-02-22
CVE-2023-51450 baserCMS OS command injection vulnerability in Installer CWE-78 5.6 Medium2024-02-22
CVE-2023-44379 baserCMS Cross-site Scripting vulnerability in Site search Feature CWE-79 6.1 Medium2024-02-22
CVE-2023-43792 baserCMS Code Injection Vulnerability in Mail Form Feature CWE-94 9.8 -2023-10-30
CVE-2023-43649 baserCMS CSRF vulnerability in Content preview Feature CWE-352 4.7 Medium2023-10-30
CVE-2023-43648 baserCMS Directory Traversal vulnerability in Form submission data management Feature CWE-22 4.9 Medium2023-10-30
CVE-2023-43647 baserCMS Cross-site Scripting vulnerability in File upload Feature CWE-79 6.1 Medium2023-10-30
CVE-2023-29009 basercms XSS Vulnerability via Favorites Feature CWE-79 6.1 Medium2023-10-27
CVE-2023-25655 baserCMS allows any file to be uploaded CWE-434 9.8 Critical2023-03-23
CVE-2023-25654 baserCMS File Uploader Remote Code Execution (RCE) vulnerability CWE-434 9.8 Critical2023-03-23
CVE-2022-41994 baserCMS 跨站脚本漏洞 4.8 -2022-12-07
CVE-2022-42486 baserCMS 跨站脚本漏洞 4.8 -2022-12-07
CVE-2022-39325 Cross-site scripting vulnerability in BaserCMS CWE-79 4.6 Medium2022-11-25
CVE-2021-41279 Zip Slip Vulnerability in BaserCMS CWE-22 7.7 High2021-11-26
CVE-2021-41243 OS Command Injection Vulnerability and Potential Zip Slip Vulnerability CWE-78 9.1 Critical2021-11-26
CVE-2021-39136 Cross-site scripting vulnerability in file upload CWE-79 8.7 High2021-08-25

All 52 known CVE vulnerabilities affecting BaserCMS with full Chinese analysis, references, and POCs where available.