Basercms is a modestly represented content-management and mail platform whose vulnerability footprint, despite a narrow product scope, places it among the more prominent vendors in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though live exploitation and public-exploit availability are tracked separately. The exposure recurs across its core CMS and mail components through web-application-layer weakness classes including cross-site scripting, cross-site request forgery, OS command injection, unrestricted file upload, and path traversal, reflecting both input-handling and access-control challenges inherent to PHP-based web platforms. Defenders deploying Basercms should prioritize input sanitization controls and restrict file-upload permissions; current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Basercms over time
Signals from CVEs in this vendor scope (68 CVEs).
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27697CRITICAL baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been patched in version 5.2.3. | Mar 31, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-30880CRITICAL baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2 | Mar 31, 2026 | 9.8 | 33 | NO | NO |
CVE-2023-25655CRITICAL baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch. | Mar 23, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-41243HIGH There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted z | Nov 26, 2021 | 8.8 | 29 | NO | NO |
CVE-2017-10842CRITICAL SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Aug 29, 2017 | 9.8 | 29 | NO | NO |
CVE-2026-30877HIGH baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated | Mar 31, 2026 | 7.2 | 28 | NO | NO |
CVE-2026-21861HIGH baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated admi | Mar 31, 2026 | 7.2 | 28 | NO | NO |
CVE-2023-43792CRITICAL baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no kn | Oct 30, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-43649CRITICAL baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 c | Oct 30, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-25654CRITICAL baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a | Mar 23, 2023 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (68 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Basercms.
Media articles that mention a CVE ID that affects a product developed by Basercms — matched by CVE ID, not by vendor name.