CVE-2026-30880 is a critical OS command injection vulnerability found in the installer component of baserCMS versions prior to 5.2.3. This flaw carries a CVSS score of 9.8 (CRITICAL) due to its network-based, low-complexity, and unauthenticated nature, allowing remote attackers to achieve complete compromise of confidentiality, integrity, and availability. While there are no known public exploits or evidence of active exploitation, the vulnerability has received some community attention, with discussions highlighting the potential for remote unauthenticated code execution. Organizations using affected baserCMS installations are strongly advised to upgrade to version 5.2.3 or later, or to restrict access to the installer, to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.3CPE matchmatch criteria | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.