CVE-2026-30880: baserCMS: OS command injection vulnerability in installer
baserCMS has an OS command injection vulnerability in the installer.
Target baserCMS 5.2.2 and earlier versions
Vulnerability
If baserCMS is placed on a server but not installed, malicious commands may be executed.
Countermeasures Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN54513170
Credits
REN XINGDIAN
Other sources
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30880?
CVE-2026-30880 is classified as a critical severity OS command injection vulnerability.
How do I fix CVE-2026-30880?
To address CVE-2026-30880, upgrade baserCMS to version 5.2.3 or later.
What versions of baserCMS are affected by CVE-2026-30880?
Versions of baserCMS prior to 5.2.3 are affected by CVE-2026-30880.
What is the impact of CVE-2026-30880 on my system?
CVE-2026-30880 allows an attacker to execute arbitrary OS commands on the server.
Is there a patch for CVE-2026-30880?
Yes, a patch for CVE-2026-30880 is included in baserCMS version 5.2.3.