basercms.net
https://basercms.net/security/JVN_20837860 CVE-2026-30880
CRITICAL
baserCMS: OS command injection vulnerability in installer
Record summary
CVE-2026-30880 has a selected CVSS score of 9.2 (critical).
Description
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 31, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
basercmsBrowse baserproject / basercms | CVE List | < 5.2.3 | affected |
baserproject/basercmsBrowse Packagist / baserproject/basercms | GitHub Advisory | Before 5.2.3 · Fixed in 5.2.3 | affected |
References
5github.com
https://github.com/baserproject/basercms github.com
https://github.com/baserproject/basercms/releases/tag/5.2.3 github.comConfirmation
https://github.com/baserproject/basercms/security/advisories/GHSA-6hpg-8rx3-cwgv nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-30880