<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:51:37.019599+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-92462</id>
    <title>cnvd-2021-92462</title>
    <updated>2026-10-05T18:51:37.023529+00:00</updated>
    <content>cnvd-2021-92462</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-92462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-31591</id>
    <title>EUVD-2026-31591</title>
    <updated>2026-10-05T18:51:37.023589+00:00</updated>
    <content>EUVD-2026-31591</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-31591"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41243</id>
    <title>fkie_cve-2021-41243</title>
    <updated>2026-10-05T18:51:37.023604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-41243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7rpc-9m88-cf9w</id>
    <title>GHSA-7rpc-9m88-cf9w — OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMS</title>
    <updated>2026-10-05T18:51:37.023648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: baserproject/basercms</p>
<p>There is an OS Command Injection Vulnerability on the management system of baserCMS.</p>
<p>This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users.
If you are eligible, please update to the new version as soon as possible.</p>
<p>Target
baserCMS 4.5.3 and earlier versions</p>
<p>Vulnerability
OS Command Injection Vulnerability.</p>
<p>Countermeasures
Update to the latest version of baserCMS</p>
<p>Credits
Akagi Yusuke @NTT-ME</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7rpc-9m88-cf9w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-41243</id>
    <title>gsd-2021-41243</title>
    <updated>2026-10-05T18:51:37.023676+00:00</updated>
    <content>gsd-2021-41243</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-41243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2021-000106</id>
    <title>jvndb-2021-000106</title>
    <updated>2026-10-05T18:51:37.023688+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>baserCMS provided by baserCMS Users Community contains multiple vulnerabilities listed below.

* OS command injection (CWE-78) - CVE-2021-41243
* Arbitrary code upload vulnerability in Database restore (CWE-434) - CVE-2021-41279

CVE-2021-41243
Akagi Yusuke of NTT-ME CORPORATION reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2021-41279
Daniele Scanu of SoterITSecurity reported this vulnerability to baserCMS Users Community and baserCMS Users Community reported it to JPCERT/CC to notify users of the solution through JVN.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2021-000106"/>
  </entry>
</feed>
