baserproject/basercms
baserCMS : Based Website Development Project
Activity
- Latest release
- 2w ago
- Total releases
- 166
- Cadence
- ~daily
- Last 12 months
- 15
Reach
- Stars
- 193
Details
- License
- MIT
- First release
- Mar 02, 2015
| Version | Released | |
|---|---|---|
5.4.0
minor
|
5.4.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
5.2.10
patch
|
5.2.10
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.0
minor
|
5.3.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.9
patch
|
5.2.9
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.8
patch
|
5.2.8
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.7
patch
| ||
5.2.6
patch
| ||
5.2.5.1
patch
| ||
5.2.5
patch
| ||
4.8.3
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.2.4
patch
| ||
5.2.3
patch
| ||
5.2.2
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev |
5.2.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.2.1
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.2.0
minor
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.10
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.9
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.8
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.7
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.6
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.5
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.4
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.3
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.21
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
4.8.2
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.0
minor
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
5.1.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
5.0.0
major
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.1
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.2
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.3
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.4
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.5
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.6
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.7
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.0.7
patch
Dependencies (8)
Changelog
Compare changes
|
|
5.0.8
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.10
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.11
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.14
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.15
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.16
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.2
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.1.1
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.17
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.18
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.19
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.20
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev |
5.0.20
patch
Dependencies (8)
Changelog
Compare changes
|
|
5.0.12
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
4.8.1
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.9
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
4.8.0
minor
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 143 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 131 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
+ 117 more Show less
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
4.8.3
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |