CVE-2026-27697
baserCMS has a SQL injection vulnerability in blog posts.
Target
baserCMS 5.2.2 and earlier versions
Vulnerability
Malicious SQL may be executed in blog posts.
Countermeasures
Update to the latest version of baserCMS
Please refer to the following page to reference for more information.
https://basercms.net/security/JVN_52157568
Credits
Mirai Matsumoto@Future Secure Wave, Inc.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/baserproject/basercms/security/advisories/GHSA-vh89-rjph-2g7p, https://nvd.nist.gov/vuln/detail/CVE-2026-27697, https://basercms.net/security/JVN_20837860, https://github.com/baserproject/basercms, https://github.com/baserproject/basercms/releases/tag/5.2.3
