Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. Join the discussion | CVE Database V5 | 09/30/2026, 07:34:09 UTC Added: 09/30/2026, 08:05:21 UTC |
A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. Join the discussion | CVE Database V5 | 09/30/2026, 07:33:53 UTC Added: 09/30/2026, 08:05:21 UTC |
0 baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a backup restore code injection flaw, where PHP code outside class definitions in schema files executes unconditionally upon loading, to plant malicious table names and trigger error-based SQL injection that retrieves database version, schema contents, and arbitrary data from the PostgreSQL backend. Join the discussion | CVE Database V5 | 08/20/2026, 13:58:05 UTC Added: 08/20/2026, 14:09:22 UTC |
0 A DOM-based cross-site scripting (XSS) vulnerability exists in baserCMS versions prior to 5.2.3 during tag creation. This vulnerability allows an attacker to inject malicious scripts that can execute in the context of a user's browser. The issue has been addressed and patched in baserCMS version 5.2.3. Join the discussion | CVE Database V5 | 03/31/2026, 00:46:43 UTC Added: 03/31/2026, 01:08:18 UTC |
0 baserCMS versions prior to 5.2.3 contain a cross-site scripting (XSS) vulnerability in blog posts due to improper neutralization of input during web page generation. This vulnerability has been addressed and patched in version 5.2.3. The CVSS 4.0 base score is 6.9, indicating a medium severity level. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 03/31/2026, 00:45:50 UTC Added: 03/31/2026, 01:08:18 UTC |
0 baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3. Join the discussion | CVE Database V5 | 03/31/2026, 00:45:35 UTC Added: 03/31/2026, 01:08:18 UTC |
baserCMS versions prior to 5.2.3 contain an improper authorization vulnerability in a public mail submission API. This flaw allows unauthenticated users to submit mail form entries even when the form is configured to reject submissions, bypassing administrative controls. The vulnerability enables potential spam or abuse through the API. A fix addressing this issue was released in version 5.2.3. Join the discussion | CVE Database V5 | 03/31/2026, 00:45:21 UTC Added: 03/31/2026, 01:08:18 UTC |
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3. Join the discussion | CVE Database V5 | 03/31/2026, 00:45:09 UTC Added: 03/31/2026, 01:08:18 UTC |
baserCMS versions prior to 5.2.3 contain an OS command injection vulnerability in the installer component. This vulnerability allows an attacker to execute arbitrary operating system commands due to improper neutralization of special elements. The issue has been addressed and patched in version 5.2.3. The vulnerability has a critical severity with a CVSS score of 9.2. Join the discussion | CVE Database V5 | 03/31/2026, 00:44:39 UTC Added: 03/31/2026, 01:08:18 UTC |
0 baserCMS versions prior to 5.2.3 contain a SQL injection vulnerability in the blog posts functionality. This vulnerability allows an attacker to inject malicious SQL commands due to improper neutralization of special elements in SQL queries. The issue has been addressed and patched in baserCMS version 5.2.3. Join the discussion | CVE Database V5 | 03/31/2026, 00:44:20 UTC Added: 03/31/2026, 01:08:18 UTC |
Showing 1 to 10 of 12 results