CVE-2026-30880

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

01 Apr 2026, 20:27

Type Values Removed Values Added
References () https://basercms.net/security/JVN_20837860 - () https://basercms.net/security/JVN_20837860 - Vendor Advisory
References () https://github.com/baserproject/basercms/releases/tag/5.2.3 - () https://github.com/baserproject/basercms/releases/tag/5.2.3 - Release Notes
References () https://github.com/baserproject/basercms/security/advisories/GHSA-6hpg-8rx3-cwgv - () https://github.com/baserproject/basercms/security/advisories/GHSA-6hpg-8rx3-cwgv - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
First Time Basercms basercms
Basercms

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) baserCMS es un framework de desarrollo de sitios web. Antes de la versión 5.2.3, baserCMS tiene una vulnerabilidad de inyección de comandos del sistema operativo en el instalador. Este problema ha sido parcheado en la versión 5.2.3.

31 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 01:16

Updated : 2026-04-01 20:27


NVD link : CVE-2026-30880

Mitre link : CVE-2026-30880

CVE.ORG link : CVE-2026-30880


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')