baserproject/basercms
baserCMS : Based Website Development Project
Activity
- Latest release
- 1d ago
- Total releases
- 165
- Cadence
- ~daily
- Last 12 months
- 15
Reach
- Stars
- 194
Details
- License
- MIT
- First release
- Mar 02, 2015
| Version | Released | |
|---|---|---|
5.2.10
patch
|
5.2.10
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.0
minor
|
5.3.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.9
patch
|
5.2.9
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.8
patch
|
5.2.8
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.7
patch
| ||
5.2.6
patch
| ||
5.2.5.1
patch
| ||
5.2.5
patch
| ||
4.8.3
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.2.4
patch
| ||
5.2.3
patch
| ||
5.2.2
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev |
5.2.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.2.1
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.2.0
minor
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.10
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.9
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.8
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.7
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.6
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.5
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.4
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.3
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.0.21
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
4.8.2
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.1.0
minor
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev |
5.1.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
5.0.0
major
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.1
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.2
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.3
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.4
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.5
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.6
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.7
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev |
5.0.7
patch
Dependencies (8)
Changelog
Compare changes
|
|
5.0.8
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.10
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.11
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.14
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.15
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.16
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.1.2
patch
9 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev | ||
5.1.1
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.17
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.18
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.19
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
5.0.20
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev |
5.0.20
patch
Dependencies (8)
Changelog
Compare changes
|
|
5.0.12
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
4.8.1
patch
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
5.0.9
patch
13 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
4.8.0
minor
16 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
4.7.8
patch
20 CVEs
CVE-2026-32734
GHSA-677c-xv24-crgx
Mar 31, 2026
baserCMS is Vulnerable to Cross-site Scripting
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
baserCMS has DOM-based cross-site scripting in tag creation. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious JavaScript may be executed when creating a tag. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_94952030 Credits
Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30940
GHSA-c5c6-37vq-pjcq
Mar 31, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
SummaryA path traversal vulnerability exists in the baserCMS 5.x theme file management API ( An authenticated administrator can include Affected CodeFile:
Attack Scenario
Reproduction Steps
Vulnerability Details| Item | Details |
|------|---------|
| CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path |
| Impact | Arbitrary file write, Remote Code Execution (RCE) |
| Attack Prerequisites | Administrator privileges + API enabled ( Additional Notes on Attack Prerequisites
Recommended FixRather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using The specific implementation location and method are left to the project's design decisions. Comparison with Other CMSWordPress's theme editor only allows editing within This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)." Resources
This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30880
GHSA-6hpg-8rx3-cwgv
Mar 31, 2026
baserCMS has OS command injection vulnerability in installer
Critical
Network
High
None
None
baserCMS has an OS command injection vulnerability in the installer. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityIf baserCMS is placed on a server but not installed, malicious commands may be executed. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_54513170 CreditsREN XINGDIAN Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30879
GHSA-jmq3-x8q7-j9qm
Mar 31, 2026
baserCMS has a cross-site scripting vulnerability in blog posts
Medium
Network
Low
None
None
baserCMS has a cross-site scripting vulnerability in blog posts. TargetbaserCMS 5.2.1 and earlier versions VulnerabilityMalicious Javascript may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_20837860 CreditsGai Tanaka@Mitsui Bussan Secure Directions, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30878
GHSA-8cr7-r8qw-gp3c
Mar 31, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
SummaryA public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. DetailsIn baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in These checks are enforced in the UI flow handled by However, the public API endpoint:
does not invoke The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI. PoC
ImpactThis is an access control / business logic bypass vulnerability. Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-30877
GHSA-m9g7-rgfc-jcm7
Mar 31, 2026
baserCMS Update Functionality Vulnerable to OS Command Injection
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryThe latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. DetailsPlease refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf ImpactAn authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-27697
GHSA-vh89-rjph-2g7p
Mar 31, 2026
baserCMS has an SQL injection vulnerability in its blog post functionality
Medium
Network
Low
None
None
baserCMS has a SQL injection vulnerability in blog posts. TargetbaserCMS 5.2.2 and earlier versions VulnerabilityMalicious SQL may be executed in blog posts. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_52157568 CreditsMirai Matsumoto@Future Secure Wave, Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2026-21861
GHSA-qxmc-6f24-g86g
Mar 31, 2026
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
SummaryIn the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session. Vulnerability Information| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) | Affected Areas
Technical DetailsVulnerable Code Flow
Relevant Code (Excerpt)PluginsController.php
PluginsService.php
The
Attack Scenario
Example Attack Input (Conceptual)
Verification Results (PoC)Execution Result
The above confirms that OS commands can be executed with Additional Notes
ImpactIf this vulnerability is exploited, the following becomes possible:
Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant. Recommended FixPrimary Recommendation
Supplementary Fix Recommendations
Alternative (Not Recommended)
However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended. Additional Notes
ConclusionDue to a design issue in baserCMS's core update functionality where user input is passed to This advisory was translated from Japanese to English using GitHub Copilot. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2025-32957
GHSA-hv78-cwp4-8r7r
Mar 31, 2026
baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)
8.7
/ 10
High
Network
Low
High
None
Changed
High
High
None
DetailsThe application's restore function allows users to upload a Vector: Malicious ZIP upload + insecure PoC
ImpactRemote Code Execution (RCE) Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 133 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.1.9
5.2.0
5.2.1
5.2.2
Fixed in
5.2.3
References Updated Mar 31, 2026 · Source: OSV.dev
CVE-2024-46998
GHSA-p3m2-mj3j-j49x
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Edit Email Form Settings Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Edit Email Form Settings feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46996
GHSA-66jv-qrm3-vvfg
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Medium
Adjacent
Low
Low
XSS vulnerability in Blog posts feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsAyato Shitomi@Fore-Z Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 28, 2024 · Source: OSV.dev
CVE-2024-46995
GHSA-mr7q-fv7j-jcgv
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
XSS vulnerability in HTTP 400 Bad Request to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in HTTP 400 Bad Request. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-46994
GHSA-wrjc-fmfq-w3jr
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
XSS vulnerability in Blog posts and Contents list Feature to baserCMS. TargetbaserCMS 5.1.1 and earlier versions VulnerabilityMalicious code may be executed in Blog posts and Contents list feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_00876083 CreditsKyohei Ota@LEON TECHNOLOGY,Inc. Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 121 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.10
5.0.11
5.0.12
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.2
5.0.20
5.0.21
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
Fixed in
5.1.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2023-44379
GHSA-66c2-p8rh-qx87
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Site search Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Site search Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.10
3.0.10.1
3.0.11
3.0.11.1
3.0.12
3.0.13
+ 107 more Show less
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.7
3.0.7.1
3.0.8
3.0.8.1
3.0.9
3.0.9.1
4.0.0
4.0.0-beta
4.0.1
4.0.10
4.0.10.1
4.0.11
4.0.2
4.0.2.1
4.0.3
4.0.4
4.0.5
4.0.5.1
4.0.5.2
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0.1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.7.1
4.4.0
4.4.1
4.4.1.1
4.4.2
4.4.2.1
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.6.0
4.6.1
4.6.1.1
4.6.2
4.6.3
4.7.0
4.7.2
4.7.3
4.7.5
4.7.6
4.7.7
4.7.8
4.8.0
4.8.1
4.8.2
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Dec 18, 2024 · Source: OSV.dev
CVE-2023-51450
GHSA-77fc-4cv5-hmfr
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
There is a OS command injection in Installer Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious command may be executed in Installer. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2024-26128
GHSA-jjxq-m8h3-4vw5
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Content Management Feature to baserCMS. TargetbaserCMS 5.0.8 and earlier versions VulnerabilityMalicious code may be executed in Content Management Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_73283159 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 53 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
5.0.0
5.0.0-beta1
5.0.0-beta2
5.0.0-beta3
5.0.0-beta4
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Fixed in
5.0.9
References
Updated Feb 22, 2024 · Source: OSV.dev
CVE-2023-43649
GHSA-fw9x-cqjq-7jx5
Oct 26, 2023
baserCMS CSRF vulnerability in Content preview Feature
4.7
/ 10
Medium
Network
Low
High
None
Unchanged
Low
Low
Low
There is a CSRF Vulnerability in Content preview Feature to baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible. TargetbaserCMS 4.7.8 and earlier versions VulnerabilityMalicious code may be executed in Content preview Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_45547161 CreditsShiga Takuma@BroadBand Security, Inc Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 38 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
Fixed in
4.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-43648
GHSA-hmqj-gv2m-hq55
Oct 26, 2023
baserCMS Directory Traversal vulnerability in Form submission data management Feature
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
There is a Directory Traversal Vulnerability in Form submission data management Feature to baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible. TargetbaserCMS 4.7.8 and earlier versions VulnerabilityThere is a possibility that information on the server may be obtained by a user who is logged in to the management screen. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_45547161 CreditsShiga Takuma@BroadBand Security, Inc Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 38 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
Fixed in
4.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-43647
GHSA-ggj4-78rm-6xgv
Oct 26, 2023
baserCMS Cross-site Scripting vulnerability in File upload Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in File upload Feature to baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible. TargetbaserCMS 4.7.8 and earlier versions VulnerabilityMalicious code may be executed in File upload Feature. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_45547161 CreditsShiga Takuma@BroadBand Security, Inc Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 38 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
Fixed in
4.8.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-29009
GHSA-8vqx-prq4-rqrq
Oct 26, 2023
baserCMS Cross-site Scripting Vulnerability in Favorites Feature
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
There is a XSS Vulnerability in Favorites Feature to baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible. TargetbaserCMS 4.7.8 and earlier versions VulnerabilityMalicious code could be executed in the Favorites feature on the server. CountermeasuresUpdate to the latest version of baserCMS Please refer to the following page to reference for more information. https://basercms.net/security/JVN_45547161 Creditsota kyohei Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
1.0.0
2.0.0
2.0.0-rc1
2.0.0-rc2
+ 40 more Show less
2.0.0-rc3
2.0.0-rc4
2.0.0-rc5
2.0.0-rc6
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.19
3.0.2
3.0.20
3.0.21
3.0.22
3.0.23
3.0.24
3.0.25
3.0.26
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.9
4.0.0
4.1.0
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.4.8
4.5.4
Fixed in
4.8.0
References
Updated Jun 25, 2024 · Source: OSV.dev |