CVE-2026-32734: baserCMS: Multiple vulnerabilities in baserCMS
baserCMS has DOM-based cross-site scripting in tag creation.
Target baserCMS 5.2.2 and earlier versions
Vulnerability Malicious JavaScript may be executed when creating a tag.
Countermeasures Update to the latest version of baserCMS
Please refer to the following page to reference for more information. https://basercms.net/security/JVN94952030
Credits
- quanlna2 (Le Nguyen Anh Quan) - namdi (Do Ich Nam) - minhnn42 (Nguyen Ngoc Minh) - VCSLab - Viettel Cyber Security
Other sources
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been patched in version 5.2.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32734?
CVE-2026-32734 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-32734?
To fix CVE-2026-32734, upgrade your baserCMS installation to version 5.2.3 or later.
What type of vulnerability is CVE-2026-32734?
CVE-2026-32734 is a DOM-based cross-site scripting vulnerability affecting tag creation in baserCMS.
Is my version of baserCMS affected by CVE-2026-32734?
If you are using a version of baserCMS prior to 5.2.3, your version is affected by CVE-2026-32734.
What component of baserCMS is impacted by CVE-2026-32734?
CVE-2026-32734 impacts the tag creation functionality within the baserCMS framework.