Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/baserproject/basercms

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

baserCMS versions prior to 5.3.0 have a high-severity SQL injection vulnerability in BcDatabaseService.php. Authenticated administrators can inject malicious table names and configuration values into SQL commands during sequence updates, CSV exports, and table management. This vulnerability can be chained with a backup restore code injection flaw that executes PHP code unconditionally from schema files, enabling attackers to retrieve database version, schema contents, and arbitrary data from the PostgreSQL backend.

Join the discussion

A DOM-based cross-site scripting (XSS) vulnerability exists in baserCMS versions prior to 5.2.3 during tag creation. This vulnerability allows an attacker to inject malicious scripts that can execute in the context of a user's browser. The issue has been addressed and patched in baserCMS version 5.2.3.

Join the discussion

baserCMS versions prior to 5.2.3 contain a cross-site scripting (XSS) vulnerability in blog posts due to improper neutralization of input during web page generation. This vulnerability has been addressed and patched in version 5.2.3. The CVSS 4.0 base score is 6.9, indicating a medium severity level. There are no known exploits in the wild at this time.

Join the discussion

baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3.

Join the discussion

baserCMS versions prior to 5.2.3 contain an improper authorization vulnerability in a public mail submission API. This flaw allows unauthenticated users to submit mail form entries even when the form is configured to reject submissions, bypassing administrative controls. The vulnerability enables potential spam or abuse through the API. A fix addressing this issue was released in version 5.2.3.

Join the discussion

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3.

Join the discussion

baserCMS versions prior to 5.2.3 contain an OS command injection vulnerability in the installer component. This vulnerability allows an attacker to execute arbitrary operating system commands due to improper neutralization of special elements. The issue has been addressed and patched in version 5.2.3. The vulnerability has a critical severity with a CVSS score of 9.2.

Join the discussion

baserCMS versions prior to 5.2.3 contain a SQL injection vulnerability in the blog posts functionality. This vulnerability allows an attacker to inject malicious SQL commands due to improper neutralization of special elements in SQL queries. The issue has been addressed and patched in baserCMS version 5.2.3.

Join the discussion

baserCMS versions prior to 5.2.3 contain a critical OS command injection vulnerability in the core update functionality. An authenticated administrator can exploit this flaw to execute arbitrary operating system commands on the server. The vulnerability arises from improper neutralization of special elements in user input passed directly to the exec() function without adequate validation or escaping. This issue has been addressed and patched in version 5.2.3.

Join the discussion

baserCMS versions prior to 5.2.3 contain a vulnerability in the restore function that allows uploading and automatic extraction of . zip files without proper validation. A malicious PHP file inside the archive can be included via require_once, leading to arbitrary code execution. This vulnerability has been patched in version 5.2.3.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/baserproject/basercms
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses