Cross-Site Scripting Vulnerability in baserCMS by baserProject
CVE-2026-30879

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-30879?

baserCMS, a website development framework by baserProject, has been found to contain a cross-site scripting vulnerability in its blog post feature. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions or data exposure. The issue affects all versions prior to 5.2.3, and users are advised to upgrade to the patched version to ensure the security of their web applications.

Affected Version(s)

basercms < 5.2.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.