CVE-2020-15276: Basercms

High severity, CVSS 8.7. EPSS: 1% chance of exploitation in the next 30 days.

baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

Affected products

  • Basercms Basercms: from 4.0.0, before 4.4.1 (fixed in 4.4.1)

Published 2020-10-30. Last modified 2026-06-17.