Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Basercms

First CVE: Oct 2, 2011Active for: 15 yearsTotal CVEs: 68
37.9
VTI Score
Medium

Basercms is a modestly represented content-management and mail platform whose vulnerability footprint, despite a narrow product scope, places it among the more prominent vendors in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though live exploitation and public-exploit availability are tracked separately. The exposure recurs across its core CMS and mail components through web-application-layer weakness classes including cross-site scripting, cross-site request forgery, OS command injection, unrestricted file upload, and path traversal, reflecting both input-handling and access-control challenges inherent to PHP-based web platforms. Defenders deploying Basercms should prioritize input sanitization controls and restrict file-upload permissions; current severity and exploitation status are shown alongside this summary.

FAUCET AI Generated
68
Total CVEs
More Total CVEs than 99% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Basercms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 2, 2011
14 years ago
Most Recent CVE
Mar 31, 2026
116 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (68 CVEs).

68 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-27697CRITICAL
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been patched in version 5.2.3.
Mar 31, 20269.834NONO
CVE-2026-30880CRITICAL
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2
Mar 31, 20269.833NONO
CVE-2023-25655CRITICAL
baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.
Mar 23, 20239.830NONO
CVE-2021-41243HIGH
There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted z
Nov 26, 20218.829NONO
CVE-2017-10842CRITICAL
SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Aug 29, 20179.829NONO
CVE-2026-30877HIGH
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated
Mar 31, 20267.228NONO
CVE-2026-21861HIGH
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated admi
Mar 31, 20267.228NONO
CVE-2023-43792CRITICAL
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no kn
Oct 30, 20239.828NONO
CVE-2023-43649CRITICAL
baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 c
Oct 30, 20239.828NONO
CVE-2023-25654CRITICAL
baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a
Mar 23, 20239.828NONO
View all 68 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products68 CVEs
49%
41%
10%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network63 (92.6%)
Unknown5 (7.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low59 (86.8%)
High4 (5.9%)
Unknown5 (7.4%)
User Interaction
None27 (39.7%)
Unknown5 (7.4%)
Required36 (52.9%)
Privileges Required
Low21 (30.9%)
High14 (20.6%)
None28 (41.2%)
Unknown5 (7.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (68 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Basercms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Basercms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Basercms's Products

View all 3 CNAs →

Top CWEs