baserproject/basercms
Packagist56 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting baserproject/basercmspage 2 of 2
- CVE-2026-30877HIGHCVSS 7.2EG 7.2✓ Fixed in 5.2.32026-03-31
vulnerable: 2.0.0-rc1 ... 5.2.2 (145 versions)
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute…
- CVE-2026-30878MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.2.32026-03-31
vulnerable: 2.0.0-rc1 ... 5.2.2 (145 versions)
baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses adminis…
- CVE-2026-30879MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.2.32026-03-31
vulnerable: 2.0.0-rc1 ... 5.2.2 (145 versions)
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.
- CVE-2026-30880CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.2.32026-03-31
vulnerable: 2.0.0-rc1 ... 5.2.2 (145 versions)
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.
- CVE-2026-30940HIGHCVSS 7.2EG 7.2✓ Fixed in 5.2.32026-03-31
vulnerable: 2.0.0-rc1 ... 5.2.2 (145 versions)
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenti…
- CVE-2026-32734MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.2.32026-03-31
vulnerable: 2.0.0-rc1 ... 5.2.2 (145 versions)
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been patched in version 5.2.3.
Check whether baserproject/basercms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for baserproject/basercms CVEs against the assets you own.
Start Free Scan →