CVE-2026-27697

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been patched in version 5.2.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

01 Apr 2026, 20:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Basercms basercms
Basercms
CPE cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
References () https://basercms.net/security/JVN_20837860 - () https://basercms.net/security/JVN_20837860 - Vendor Advisory
References () https://github.com/baserproject/basercms/releases/tag/5.2.3 - () https://github.com/baserproject/basercms/releases/tag/5.2.3 - Release Notes
References () https://github.com/baserproject/basercms/security/advisories/GHSA-vh89-rjph-2g7p - () https://github.com/baserproject/basercms/security/advisories/GHSA-vh89-rjph-2g7p - Vendor Advisory

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) baserCMS es un framework de desarrollo de sitios web. Antes de la versión 5.2.3, baserCMS tiene una vulnerabilidad de inyección SQL en las publicaciones de blog. Este problema ha sido parcheado en la versión 5.2.3.

31 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 01:16

Updated : 2026-04-01 20:29


NVD link : CVE-2026-27697

Mitre link : CVE-2026-27697

CVE.ORG link : CVE-2026-27697


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')