CVE-2020-15154: Basercms
High severity, CVSS 7.3. EPSS: 1% chance of exploitation in the next 30 days.
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php, index_list_tree.php, jquery.bcTree.js. The issue is fixed in version 4.3.7.
Affected products
- Basercms Basercms: up to and including 4.3.6
Published 2020-08-28. Last modified 2026-06-17.