Description
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.
Published: 2026-03-31
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

baserCMS, prior to version 5.2.3, includes a cross‑site scripting vulnerability in the blog post component. An attacker who can insert malicious code into a blog entry can cause that code to be executed in the web browsers of any visitor who views the post. The flaw, classified as CWE‑79, allows arbitrary script execution on the client side, which can compromise the confidentiality and integrity of user data displayed by the site.

Affected Systems

All installations of baserCMS with a version earlier than 5.2.3 are affected. The vendor released a patch in version 5.2.3 that removes the vulnerability; newer releases are not susceptible.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker requires the ability to create or edit blog posts, which may require authenticated authoring privileges. Because the malicious script would run in the browsers of all site visitors, the practical impact can be significant for sites that allow open or lightly protected posting authority. The overall risk is moderate but warrants prompt remediation.

Generated by OpenCVE AI on March 31, 2026 at 06:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade baserCMS to version 5.2.3 or later

Generated by OpenCVE AI on March 31, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jmq3-x8q7-j9qm baserCMS has a cross-site scripting vulnerability in blog posts
History

Tue, 31 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Description baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.
Title baserCMS: Cross-site scripting vulnerability in blog post
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-31T14:00:32.272Z

Reserved: 2026-03-06T00:04:56.699Z

Link: CVE-2026-30879

cve-icon Vulnrichment

Updated: 2026-03-31T14:00:28.392Z

cve-icon NVD

Status : Received

Published: 2026-03-31T01:16:36.127

Modified: 2026-03-31T01:16:36.127

Link: CVE-2026-30879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-31T19:56:38Z

Weaknesses