CVE-2026-93460: XSS
Published Sep 30, 2026
·Updated
Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
Affected Software
1 affected component
baserCMS BaserCMS
Event History
Sep 30, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs at least low-level privileges and must induce a user to interact with the stored cross-site scripting payload. The attack is network-accessible and has low attack complexity.
2
What is the likely impact if exploitation succeeds?
A script can execute in the affected user's browser. The provided vector indicates low confidentiality and integrity impact, no availability impact, and a scope change.