DOM-Based Cross-Site Scripting in baserCMS by baserProject
CVE-2026-32734

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-32734?

A security issue was identified in baserCMS, a website development framework, where prior to version 5.2.3, a DOM-based cross-site scripting vulnerability existed in the tag creation functionality. This flaw could be exploited by attackers to execute arbitrary scripts in the context of affected users. It is crucial for users of baserCMS to upgrade to version 5.2.3 or later to mitigate this risk and ensure enhanced security.

Affected Version(s)

basercms < 5.2.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.