OS Command Injection Vulnerability in baserCMS Installation Framework
CVE-2026-30880

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-30880?

An OS command injection vulnerability exists in the installer of baserCMS, a widely used website development framework. This flaw, present in versions prior to 5.2.3, allows attackers to execute arbitrary commands on the underlying operating system. This could lead to severe security breaches, granting unauthorized access to system resources or sensitive data. Users are strongly advised to upgrade to version 5.2.3 or later to mitigate this risk.

Affected Version(s)

basercms < 5.2.3

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.