Technology · Packagist
baserproject/basercms (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 46 vulnerabilities in baserproject/basercms (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-32734, was published on 31 March 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest baserproject/basercms (Packagist) vulnerabilities
- CVE-2026-32734: baserCMS is Vulnerable to Cross-site ScriptinglowCVSS 3.1EPSS 0.3%
- CVE-2026-30940: baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File APIlowCVSS 3.1EPSS 1.1%
- CVE-2026-30880: baserCMS has OS command injection vulnerability in installermediumCVSS 4EPSS 2.3%
- CVE-2026-30879: baserCMS has a cross-site scripting vulnerability in blog postsmediumCVSS 4EPSS 0.3%
- CVE-2026-30878: baserCMS has Mail Form Acceptance Bypass via Public APIlowCVSS 3.1EPSS 0.4%
- CVE-2026-30877: baserCMS Update Functionality Vulnerable to OS Command InjectionlowCVSS 3.1EPSS 2.1%
- CVE-2026-27697: baserCMS has an SQL injection vulnerability in its blog post functionalitymediumCVSS 4EPSS 0.5%
- CVE-2026-21861: baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)lowCVSS 3.1EPSS 2.3%
- CVE-2025-32957: baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)lowCVSS 3.1EPSS 0.6%
- CVE-2024-46998: baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings FeaturelowCVSS 3.1EPSS 0.3%
- CVE-2024-46996: baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts FeaturelowCVSS 3.1EPSS 0.3%
- CVE-2024-46995: baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad RequestlowCVSS 3EPSS 0.3%
- CVE-2024-46994: baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list FeaturelowCVSS 3EPSS 0.3%
- CVE-2023-44379: baserCMS Cross-site Scripting vulnerability in Site search FeaturelowCVSS 3.1EPSS 0.5%
- CVE-2023-51450: baserCMS OS command injection vulnerability in InstallerlowCVSS 3.1EPSS 1.5%
- CVE-2024-26128: baserCMS Cross-site Scripting vulnerability in Content ManagementlowCVSS 3.1EPSS 0.6%
- CVE-2023-43792: baserCMS Code Injection Vulnerability in Mail Form FeaturelowCVSS 3EPSS 0.6%
- CVE-2023-43649: baserCMS CSRF vulnerability in Content preview FeaturelowCVSS 3EPSS 0.4%
- CVE-2023-43648: baserCMS Directory Traversal vulnerability in Form submission data management FeaturelowCVSS 3EPSS 1.0%
- CVE-2023-43647: baserCMS Cross-site Scripting vulnerability in File upload FeaturelowCVSS 3EPSS 0.5%
- CVE-2023-29009: baserCMS Cross-site Scripting Vulnerability in Favorites FeaturelowCVSS 3.1EPSS 0.5%
- CVE-2023-25655: baserCMS allows any file to be uploadedlowCVSS 3.1EPSS 1.1%
- CVE-2023-25654: baserCMS File Uploader Remote Code Execution (RCE) vulnerabilitylowCVSS 3.1EPSS 1.5%
- CVE-2022-42486: baserCMS vulnerable to stored Cross-site ScriptinglowCVSS 3.1EPSS 0.6%
- CVE-2022-41994: baserCMS vulnerable to stored Cross-site ScriptinglowCVSS 3.1EPSS 0.6%
Most severe baserproject/basercms (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-30880: baserCMS has OS command injection vulnerability in installermediumCVSS 4EPSS 2.3%
- CVE-2026-27697: baserCMS has an SQL injection vulnerability in its blog post functionalitymediumCVSS 4EPSS 0.5%
- CVE-2026-30879: baserCMS has a cross-site scripting vulnerability in blog postsmediumCVSS 4EPSS 0.3%
- CVE-2021-20682: OS Command Injection in baserCMSlowCVSS 3.1EPSS 2.5%
- CVE-2020-15277: Edit template, Remote Code Execution (RCE) Vulnerability in Latest Release 4.4.0lowCVSS 3.1EPSS 2.3%
- CVE-2026-21861: baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)lowCVSS 3.1EPSS 2.3%
- CVE-2021-41243: OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMSlowCVSS 3.1EPSS 2.2%
- CVE-2020-15159: Cross Site Scripting and RCE in baserCMSlowCVSS 3.1EPSS 2.1%
- CVE-2026-30877: baserCMS Update Functionality Vulnerable to OS Command InjectionlowCVSS 3.1EPSS 2.1%
- CVE-2021-41279: Potential Zip Slip Vulnerability in baserCMSlowCVSS 3.1EPSS 1.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/baserproject-basercms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "baserproject/basercms (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/baserproject-basercms, 28 September 2026.