baserCMS是baserCMS团队的一套企业级内容管理系统(CMS)。 baserCMS 5.2.3之前版本存在安全漏洞,该漏洞源于应用程序的还原功能允许用户上传zip文件并自动解压,且未验证或限制文件名,可能导致攻击者通过特制PHP文件实现任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| baserproject | basercms | < 5.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: RCE_SUCCESS uid=0 user=root time=2026-05-30 18:58:39
| CVE-2026-21861 | 9.1 CRITICAL | baserCMS: OS Command Injection Leading to Remote Code Execution (RCE) |
| CVE-2026-30877 | 9.1 CRITICAL | baserCMS: OS Command Injection in the baserCMS Update Functionality |
| CVE-2026-30940 | 7.2 HIGH | baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE |
| CVE-2026-32734 | 7.1 HIGH | baserCMS: Multiple vulnerabilities in baserCMS |
| CVE-2026-30878 | 5.3 MEDIUM | baserCMS: Mail Form Acceptance Bypass via Public API |
| CVE-2026-27697 | baserCMS: SQL injection vulnerability in blog post | |
| CVE-2026-30880 | baserCMS: OS command injection vulnerability in installer | |
| CVE-2026-30879 | baserCMS: Cross-site scripting vulnerability in blog post |
No comments yet