CVE-2026-27697 is a critical SQL injection vulnerability (CWE-89) affecting baserCMS, a website development framework, in versions prior to 5.2.3. Rated with a CVSS score of 9.8, this flaw allows an unauthenticated attacker to remotely execute arbitrary SQL queries with low attack complexity, leading to a complete compromise of confidentiality, integrity, and availability. While it is listed on a "Hot List" and has some community discussion, there is currently no public exploit code available in common databases like Metasploit or ExploitDB, and it is not yet in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.3CPE matchmatch criteria | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.