CVE-2026-30880
baserCMS has an OS command injection vulnerability in the installer.
Target
baserCMS 5.2.2 and earlier versions
Vulnerability
If baserCMS is placed on a server but not installed, malicious commands may be executed.
Countermeasures
Update to the latest version of baserCMS
Please refer to the following page to reference for more information.
https://basercms.net/security/JVN_54513170
Credits
REN XINGDIAN
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/baserproject/basercms/security/advisories/GHSA-6hpg-8rx3-cwgv, https://nvd.nist.gov/vuln/detail/CVE-2026-30880, https://basercms.net/security/JVN_20837860, https://github.com/baserproject/basercms, https://github.com/baserproject/basercms/releases/tag/5.2.3
