SQL Injection Vulnerability in baserCMS Product by baserProject
CVE-2026-76635

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-76635?

The baserCMS software prior to version 5.3.0 suffers from a SQL injection vulnerability within the BcDatabaseService.php file. This issue enables authenticated administrators to inject malicious table names and configuration values into SQL statements during various operations such as sequence updates, CSV exports, and table management. Moreover, this vulnerability can be exploited in conjunction with a backup restore code injection flaw, allowing PHP code outside class definitions in schema files to execute unconditionally upon loading. This creates opportunities for attackers to trigger error-based SQL injections, potentially exposing sensitive database information like version details, schema contents, and arbitrary data from the PostgreSQL backend.

Affected Version(s)

basercms 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Neo by ProjectDiscovery
.