baserCMS是baserCMS团队的一套企业级内容管理系统(CMS)。 baserCMS 5.2.3之前版本存在操作系统命令注入漏洞,该漏洞源于安装程序核心模块中,攻击者可构造包含恶意系统命令的特制请求,以 web 服务进程的权限执行任意操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| baserproject | basercms | < 5.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-21861 | 9.1 CRITICAL | baserCMS: OS Command Injection Leading to Remote Code Execution (RCE) |
| CVE-2026-30877 | 9.1 CRITICAL | baserCMS: OS Command Injection in the baserCMS Update Functionality |
| CVE-2025-32957 | 8.7 HIGH | baserCMS: unsafe File Upload Leading to Remote Code Execution (RCE) |
| CVE-2026-30940 | 7.2 HIGH | baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE |
| CVE-2026-32734 | 7.1 HIGH | baserCMS: Multiple vulnerabilities in baserCMS |
| CVE-2026-30878 | 5.3 MEDIUM | baserCMS: Mail Form Acceptance Bypass via Public API |
| CVE-2026-27697 | baserCMS: SQL injection vulnerability in blog post | |
| CVE-2026-30879 | baserCMS: Cross-site scripting vulnerability in blog post |
No comments yet