PT-2026-29148 · Basercms · Basercms

Ericueda

·

Published

2026-03-31

·

Updated

2026-04-02

·

CVE-2026-30877

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions baserCMS versions prior to 5.2.3
Description baserCMS is a website development framework. A security issue exists in the update functionality that allows an authenticated user with administrator privileges to execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. The issue is due to an OS command injection.
Recommendations Update to version 5.2.3 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30877
GHSA-M9G7-RGFC-JCM7

Affected Products

Basercms