PT-2026-29147 · Basercms · Basercms

·

CVE-2026-27697

·

Published

2026-03-31

·

Updated

2026-03-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions baserCMS versions prior to 5.2.3
Description baserCMS is a website development framework. Prior to version 5.2.3, it contains a SQL injection flaw within blog posts. The issue allows for potential unauthorized access or modification of data through crafted SQL queries. The vulnerable component is related to the processing of blog post content. The blog posts functionality is affected.
Recommendations Update baserCMS to version 5.2.3 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27697
GHSA-VH89-RJPH-2G7P

Affected Products

Basercms