Path Traversal Vulnerability in baserCMS Affecting Theme File Management API
CVE-2026-30940
7.2HIGH
What is CVE-2026-30940?
A vulnerability in baserCMS's theme file management API allows authenticated administrators to exploit a path traversal flaw. By manipulating the path parameter with ../ sequences, an attacker can write arbitrary PHP files to directories outside the designated theme directory, potentially leading to remote code execution. This critical issue, affecting baserCMS versions prior to 5.2.3, has been addressed in the latest release.
Affected Version(s)
basercms < 5.2.3
