CVE-2026-30877OS Command Injection in Basercms

Severity
7.2HIGHNVD
EPSS
0.2%
top 57.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31

Description

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

NVDbasercms/basercms< 5.2.3
CVEListV5baserproject/basercms< 5.2.3
Packagistbaserproject/basercms< 5.2.3

🔴Vulnerability Details

2
GHSA
baserCMS Update Functionality Vulnerable to OS Command Injection2026-03-31
OSV
baserCMS Update Functionality Vulnerable to OS Command Injection2026-03-31

🕵️Threat Intelligence

1
Wiz
CVE-2026-30877 Impact, Exploitability, and Mitigation Steps | Wiz