PT-2026-29148 · Baserproject · Basercms

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-30877

CVSS v3.1

9.1

Critical

AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30877

Affected Products

Basercms