{"schema_version":1,"title":"baserproject/basercms (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 46 vulnerabilities in baserproject/basercms (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-32734, was published on 31 March 2026.","url":"https://junglewise.ai/threats/technologies/baserproject-basercms","json_url":"https://junglewise.ai/threats/technologies/baserproject-basercms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/baserproject-basercms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":46,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":9},"latest":[{"cve":"CVE-2026-32734","cvss":3.1,"epss":0.0033,"slug":"cve-2026-32734-basercms-is-vulnerable-to-cross-site-scripting","title":"baserCMS is Vulnerable to Cross-site Scripting","severity":"low","exploited":false,"published_at":"2026-03-31T22:52:07+00:00","url":"https://junglewise.ai/threats/cve-2026-32734-basercms-is-vulnerable-to-cross-site-scripting"},{"cve":"CVE-2026-30940","cvss":3.1,"epss":0.0108,"slug":"cve-2026-30940-basercms-path-traversal-leads-to-arbitrary-file-write-and-rce-via","title":"baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API","severity":"low","exploited":false,"published_at":"2026-03-31T22:47:39+00:00","url":"https://junglewise.ai/threats/cve-2026-30940-basercms-path-traversal-leads-to-arbitrary-file-write-and-rce-via"},{"cve":"CVE-2026-30880","cvss":4,"epss":0.0225,"slug":"cve-2026-30880-basercms-has-os-command-injection-vulnerability-in-installer","title":"baserCMS has OS command injection vulnerability in installer","severity":"medium","exploited":false,"published_at":"2026-03-31T22:43:31+00:00","url":"https://junglewise.ai/threats/cve-2026-30880-basercms-has-os-command-injection-vulnerability-in-installer"},{"cve":"CVE-2026-30879","cvss":4,"epss":0.0032,"slug":"cve-2026-30879-basercms-has-a-cross-site-scripting-vulnerability-in-blog-posts","title":"baserCMS has a cross-site scripting vulnerability in blog posts","severity":"medium","exploited":false,"published_at":"2026-03-31T22:43:10+00:00","url":"https://junglewise.ai/threats/cve-2026-30879-basercms-has-a-cross-site-scripting-vulnerability-in-blog-posts"},{"cve":"CVE-2026-30878","cvss":3.1,"epss":0.0045,"slug":"cve-2026-30878-basercms-has-mail-form-acceptance-bypass-via-public-api","title":"baserCMS has Mail Form Acceptance Bypass via Public API","severity":"low","exploited":false,"published_at":"2026-03-31T22:36:18+00:00","url":"https://junglewise.ai/threats/cve-2026-30878-basercms-has-mail-form-acceptance-bypass-via-public-api"},{"cve":"CVE-2026-30877","cvss":3.1,"epss":0.0206,"slug":"cve-2026-30877-basercms-update-functionality-vulnerable-to-os-command-injection","title":"baserCMS Update Functionality Vulnerable to OS Command Injection","severity":"low","exploited":false,"published_at":"2026-03-31T22:35:47+00:00","url":"https://junglewise.ai/threats/cve-2026-30877-basercms-update-functionality-vulnerable-to-os-command-injection"},{"cve":"CVE-2026-27697","cvss":4,"epss":0.0054,"slug":"cve-2026-27697-basercms-has-an-sql-injection-vulnerability-in-its-blog-post","title":"baserCMS has an SQL injection vulnerability in its blog post functionality","severity":"medium","exploited":false,"published_at":"2026-03-31T22:35:08+00:00","url":"https://junglewise.ai/threats/cve-2026-27697-basercms-has-an-sql-injection-vulnerability-in-its-blog-post"},{"cve":"CVE-2026-21861","cvss":3.1,"epss":0.0228,"slug":"cve-2026-21861-basercms-has-os-command-injection-leading-to-remote-code","title":"baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)","severity":"low","exploited":false,"published_at":"2026-03-31T22:27:05+00:00","url":"https://junglewise.ai/threats/cve-2026-21861-basercms-has-os-command-injection-leading-to-remote-code"},{"cve":"CVE-2025-32957","cvss":3.1,"epss":0.0058,"slug":"cve-2025-32957-basercms-has-unsafe-file-upload-leading-to-remote-code-execution","title":"baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)","severity":"low","exploited":false,"published_at":"2026-03-31T22:22:18+00:00","url":"https://junglewise.ai/threats/cve-2025-32957-basercms-has-unsafe-file-upload-leading-to-remote-code-execution"},{"cve":"CVE-2024-46998","cvss":3.1,"epss":0.0034,"slug":"cve-2024-46998-basercms-has-a-cross-site-scripting-xss-vulnerability-in-edit","title":"baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature","severity":"low","exploited":false,"published_at":"2024-10-24T17:45:58+00:00","url":"https://junglewise.ai/threats/cve-2024-46998-basercms-has-a-cross-site-scripting-xss-vulnerability-in-edit"},{"cve":"CVE-2024-46996","cvss":3.1,"epss":0.0031,"slug":"cve-2024-46996-basercms-has-a-cross-site-scripting-xss-vulnerability-in-blog","title":"baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature","severity":"low","exploited":false,"published_at":"2024-10-24T17:45:09+00:00","url":"https://junglewise.ai/threats/cve-2024-46996-basercms-has-a-cross-site-scripting-xss-vulnerability-in-blog"},{"cve":"CVE-2024-46995","cvss":3,"epss":0.0033,"slug":"cve-2024-46995-basercms-has-a-cross-site-scripting-xss-vulnerability-in-http-400","title":"baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request","severity":"low","exploited":false,"published_at":"2024-10-24T17:44:21+00:00","url":"https://junglewise.ai/threats/cve-2024-46995-basercms-has-a-cross-site-scripting-xss-vulnerability-in-http-400"},{"cve":"CVE-2024-46994","cvss":3,"epss":0.0029,"slug":"cve-2024-46994-basercms-has-a-cross-site-scripting-xss-vulnerability-in-blog","title":"baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature","severity":"low","exploited":false,"published_at":"2024-10-24T17:43:42+00:00","url":"https://junglewise.ai/threats/cve-2024-46994-basercms-has-a-cross-site-scripting-xss-vulnerability-in-blog"},{"cve":"CVE-2023-44379","cvss":3.1,"epss":0.0047,"slug":"cve-2023-44379-basercms-cross-site-scripting-vulnerability-in-site-search","title":"baserCMS Cross-site Scripting vulnerability in Site search Feature","severity":"low","exploited":false,"published_at":"2024-02-22T19:43:32+00:00","url":"https://junglewise.ai/threats/cve-2023-44379-basercms-cross-site-scripting-vulnerability-in-site-search"},{"cve":"CVE-2023-51450","cvss":3.1,"epss":0.0146,"slug":"cve-2023-51450-basercms-os-command-injection-vulnerability-in-installer","title":"baserCMS OS command injection vulnerability in Installer","severity":"low","exploited":false,"published_at":"2024-02-22T19:43:19+00:00","url":"https://junglewise.ai/threats/cve-2023-51450-basercms-os-command-injection-vulnerability-in-installer"},{"cve":"CVE-2024-26128","cvss":3.1,"epss":0.0057,"slug":"cve-2024-26128-basercms-cross-site-scripting-vulnerability-in-content-management","title":"baserCMS Cross-site Scripting vulnerability in Content Management","severity":"low","exploited":false,"published_at":"2024-02-22T19:35:55+00:00","url":"https://junglewise.ai/threats/cve-2024-26128-basercms-cross-site-scripting-vulnerability-in-content-management"},{"cve":"CVE-2023-43792","cvss":3,"epss":0.0057,"slug":"cve-2023-43792-basercms-code-injection-vulnerability-in-mail-form-feature","title":"baserCMS Code Injection Vulnerability in Mail Form Feature","severity":"low","exploited":false,"published_at":"2023-10-26T20:52:27+00:00","url":"https://junglewise.ai/threats/cve-2023-43792-basercms-code-injection-vulnerability-in-mail-form-feature"},{"cve":"CVE-2023-43649","cvss":3,"epss":0.0035,"slug":"cve-2023-43649-basercms-csrf-vulnerability-in-content-preview-feature","title":"baserCMS CSRF vulnerability in Content preview Feature","severity":"low","exploited":false,"published_at":"2023-10-26T20:48:44+00:00","url":"https://junglewise.ai/threats/cve-2023-43649-basercms-csrf-vulnerability-in-content-preview-feature"},{"cve":"CVE-2023-43648","cvss":3,"epss":0.0097,"slug":"cve-2023-43648-basercms-directory-traversal-vulnerability-in-form-submission","title":"baserCMS Directory Traversal vulnerability in Form submission data management Feature","severity":"low","exploited":false,"published_at":"2023-10-26T20:47:57+00:00","url":"https://junglewise.ai/threats/cve-2023-43648-basercms-directory-traversal-vulnerability-in-form-submission"},{"cve":"CVE-2023-43647","cvss":3,"epss":0.0051,"slug":"cve-2023-43647-basercms-cross-site-scripting-vulnerability-in-file-upload","title":"baserCMS Cross-site Scripting vulnerability in File upload Feature","severity":"low","exploited":false,"published_at":"2023-10-26T20:47:36+00:00","url":"https://junglewise.ai/threats/cve-2023-43647-basercms-cross-site-scripting-vulnerability-in-file-upload"},{"cve":"CVE-2023-29009","cvss":3.1,"epss":0.0047,"slug":"cve-2023-29009-basercms-cross-site-scripting-vulnerability-in-favorites-feature","title":"baserCMS Cross-site Scripting Vulnerability in Favorites Feature","severity":"low","exploited":false,"published_at":"2023-10-26T20:47:17+00:00","url":"https://junglewise.ai/threats/cve-2023-29009-basercms-cross-site-scripting-vulnerability-in-favorites-feature"},{"cve":"CVE-2023-25655","cvss":3.1,"epss":0.0109,"slug":"cve-2023-25655-basercms-allows-any-file-to-be-uploaded","title":"baserCMS allows any file to be uploaded","severity":"low","exploited":false,"published_at":"2023-03-23T20:00:10+00:00","url":"https://junglewise.ai/threats/cve-2023-25655-basercms-allows-any-file-to-be-uploaded"},{"cve":"CVE-2023-25654","cvss":3.1,"epss":0.0153,"slug":"cve-2023-25654-basercms-file-uploader-remote-code-execution-rce-vulnerability","title":"baserCMS File Uploader Remote Code Execution (RCE) vulnerability","severity":"low","exploited":false,"published_at":"2023-03-23T20:00:08+00:00","url":"https://junglewise.ai/threats/cve-2023-25654-basercms-file-uploader-remote-code-execution-rce-vulnerability"},{"cve":"CVE-2022-42486","cvss":3.1,"epss":0.006,"slug":"cve-2022-42486-basercms-vulnerable-to-stored-cross-site-scripting","title":"baserCMS vulnerable to stored Cross-site Scripting","severity":"low","exploited":false,"published_at":"2022-12-07T06:30:26+00:00","url":"https://junglewise.ai/threats/cve-2022-42486-basercms-vulnerable-to-stored-cross-site-scripting"},{"cve":"CVE-2022-41994","cvss":3.1,"epss":0.006,"slug":"cve-2022-41994-basercms-vulnerable-to-stored-cross-site-scripting","title":"baserCMS vulnerable to stored Cross-site Scripting","severity":"low","exploited":false,"published_at":"2022-12-07T06:30:26+00:00","url":"https://junglewise.ai/threats/cve-2022-41994-basercms-vulnerable-to-stored-cross-site-scripting"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"baserproject/basercms (Packagist)","slug":"baserproject-basercms","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/baserproject-basercms"},"most_severe":[{"cve":"CVE-2026-30880","cvss":4,"epss":0.0225,"slug":"cve-2026-30880-basercms-has-os-command-injection-vulnerability-in-installer","title":"baserCMS has OS command injection vulnerability in installer","severity":"medium","exploited":false,"published_at":"2026-03-31T22:43:31+00:00","url":"https://junglewise.ai/threats/cve-2026-30880-basercms-has-os-command-injection-vulnerability-in-installer"},{"cve":"CVE-2026-27697","cvss":4,"epss":0.0054,"slug":"cve-2026-27697-basercms-has-an-sql-injection-vulnerability-in-its-blog-post","title":"baserCMS has an SQL injection vulnerability in its blog post functionality","severity":"medium","exploited":false,"published_at":"2026-03-31T22:35:08+00:00","url":"https://junglewise.ai/threats/cve-2026-27697-basercms-has-an-sql-injection-vulnerability-in-its-blog-post"},{"cve":"CVE-2026-30879","cvss":4,"epss":0.0032,"slug":"cve-2026-30879-basercms-has-a-cross-site-scripting-vulnerability-in-blog-posts","title":"baserCMS has a cross-site scripting vulnerability in blog posts","severity":"medium","exploited":false,"published_at":"2026-03-31T22:43:10+00:00","url":"https://junglewise.ai/threats/cve-2026-30879-basercms-has-a-cross-site-scripting-vulnerability-in-blog-posts"},{"cve":"CVE-2021-20682","cvss":3.1,"epss":0.0248,"slug":"cve-2021-20682-os-command-injection-in-basercms","title":"OS Command Injection in baserCMS","severity":"low","exploited":false,"published_at":"2021-06-08T20:10:37+00:00","url":"https://junglewise.ai/threats/cve-2021-20682-os-command-injection-in-basercms"},{"cve":"CVE-2020-15277","cvss":3.1,"epss":0.0231,"slug":"cve-2020-15277-edit-template-remote-code-execution-rce-vulnerability-in-latest","title":"Edit template, Remote Code Execution (RCE) Vulnerability in Latest Release 4.4.0","severity":"low","exploited":false,"published_at":"2020-10-30T17:05:59+00:00","url":"https://junglewise.ai/threats/cve-2020-15277-edit-template-remote-code-execution-rce-vulnerability-in-latest"},{"cve":"CVE-2026-21861","cvss":3.1,"epss":0.0228,"slug":"cve-2026-21861-basercms-has-os-command-injection-leading-to-remote-code","title":"baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)","severity":"low","exploited":false,"published_at":"2026-03-31T22:27:05+00:00","url":"https://junglewise.ai/threats/cve-2026-21861-basercms-has-os-command-injection-leading-to-remote-code"},{"cve":"CVE-2021-41243","cvss":3.1,"epss":0.0217,"slug":"cve-2021-41243-os-command-injection-vulnerability-and-potential-zip-slip","title":"OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMS","severity":"low","exploited":false,"published_at":"2021-12-01T18:29:42+00:00","url":"https://junglewise.ai/threats/cve-2021-41243-os-command-injection-vulnerability-and-potential-zip-slip"},{"cve":"CVE-2020-15159","cvss":3.1,"epss":0.0215,"slug":"cve-2020-15159-cross-site-scripting-and-rce-in-basercms","title":"Cross Site Scripting and RCE in baserCMS","severity":"low","exploited":false,"published_at":"2020-08-28T21:45:15+00:00","url":"https://junglewise.ai/threats/cve-2020-15159-cross-site-scripting-and-rce-in-basercms"},{"cve":"CVE-2026-30877","cvss":3.1,"epss":0.0206,"slug":"cve-2026-30877-basercms-update-functionality-vulnerable-to-os-command-injection","title":"baserCMS Update Functionality Vulnerable to OS Command Injection","severity":"low","exploited":false,"published_at":"2026-03-31T22:35:47+00:00","url":"https://junglewise.ai/threats/cve-2026-30877-basercms-update-functionality-vulnerable-to-os-command-injection"},{"cve":"CVE-2021-41279","cvss":3.1,"epss":0.0162,"slug":"cve-2021-41279-potential-zip-slip-vulnerability-in-basercms","title":"Potential Zip Slip Vulnerability in baserCMS","severity":"low","exploited":false,"published_at":"2021-12-01T18:29:32+00:00","url":"https://junglewise.ai/threats/cve-2021-41279-potential-zip-slip-vulnerability-in-basercms"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}