CVE-2020-15277: Basercms
High severity, CVSS 7.2. EPSS: 2.3% chance of exploitation in the next 30 days.
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.
Affected products
- Basercms Basercms: from 4.0.0, before 4.4.1 (fixed in 4.4.1)
Published 2020-10-30. Last modified 2026-06-17.