CVE-2018-18942: Basercms

High severity, CVSS 7.2. EPSS: 2.4% chance of exploitation in the next 30 days.

In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.

Affected products

  • Basercms Basercms: before 4.1.4 (fixed in 4.1.4)

Published 2018-11-05. Last modified 2026-06-17.