Description
Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
Published: 2026-09-30
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Browser‑based Code Execution
Action: Apply Patch
AI Analysis

Impact

Stored Cross‑Site Scripting is present in baserCMS when strings are appended to email form fields without proper validation or escaping. Based on the description, it is inferred that the attack vector involves an attacker crafting an email that includes malicious script, which will be stored and later served to users viewing the email form. When a victim opens the affected page, the script executes in the victim’s browser, potentially stealing credentials, session cookies, or performing other client‑side attacks. This flaw falls under the identified weakness CWE‑79 and threatens confidentiality, integrity, and availability of user data within the application.

Affected Systems

The vulnerabilities affect the baserCMS platform distributed by User Community:baserCMS. No specific version range is listed, so all installations of baserCMS that use the email form feature remain at risk until a patch is applied.

Risk and Exploitability

With a CVSS score of 5.1, the flaw is considered moderate in severity. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, suggesting limited evidence of active exploitation. Based on the description, it is inferred that the attack vector requires an attacker to craft an email with malicious content and rely on the target system rendering it. The impact is limited to users who view the affected form, but the ability to drive arbitrary JavaScript in users’ browsers presents a significant threat.

Generated by OpenCVE AI on September 30, 2026 at 12:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest baserCMS release that removes the unescaped string concatenation bug
  • Apply any vendor‑supplied filter or sanitization to all email form inputs if a patch is unavailable
  • Configure a Content Security Policy that restricts inline scripts and forces non‑inline script execution

Generated by OpenCVE AI on September 30, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting via Email Form Fields in baserCMS

Wed, 30 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Basercms Users Community
Basercms Users Community basercms
Vendors & Products Basercms Users Community
Basercms Users Community basercms

Wed, 30 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Basercms Users Community Basercms
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T07:34:09.776Z

Reserved: 2026-09-18T01:11:35.023Z

Link: CVE-2026-93460

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:35.640

Modified: 2026-09-30T08:16:35.640

Link: CVE-2026-93460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')