CVE-2026-30880
CRITICALbaserCMS: OS command injection vulnerability in installer
Title source: cnaDescription
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.
References (3)
Core 3
Core References
X_Refsource_Misc x_refsource_misc
https://basercms.net/security/JVN_20837860
X_Refsource_Confirm x_refsource_confirm
https://github.com/baserproject/basercms/security/advisories/GHSA-6hpg-8rx3-cwgv
X_Refsource_Misc x_refsource_misc
https://github.com/baserproject/basercms/releases/tag/5.2.3
Scores
CVSS v3
9.8
EPSS
0.0206
EPSS Percentile
78.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (3)
basercms/basercms
< 5.2.3
baserproject/basercms
0 - 5.2.3Packagist
baserproject/basercms
< 5.2.3
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026