Description
Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
Published: 2026-09-30
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability is a moderate‑severity cross‑site scripting flaw caused by a script validation bypass in baserCMS. An attacker can inject arbitrary JavaScript that will run in a victim’s browser when the content is displayed, enabling session hijacking, data theft, or defacement. The weakness is categorized as CWE‑79.

Affected Systems

The flaw impacts the baserCMS web application; no specific product version is listed, so any deploying instance that has not applied a vendor patch may be susceptible.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate risk. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, implying a lower likelihood of exploitation at present. The attack vector is remote, relying on the attacker’s ability to submit or modify content that bypasses the script validation check, thereby executing malicious code in users’ browsers.

Generated by OpenCVE AI on September 30, 2026 at 12:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest baserCMS release that contains a fix for the script validation bypass.
  • Sanitize all user‑supplied content and remove or encode any script tags before rendering them to browsers.
  • Configure a strict content‑security‑policy header to block the execution of inline scripts and enforce the loading of scripts only from trusted sources.

Generated by OpenCVE AI on September 30, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Script Validation Bypass in baserCMS

Wed, 30 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Basercms Users Community
Basercms Users Community basercms
Vendors & Products Basercms Users Community
Basercms Users Community basercms

Wed, 30 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Basercms Users Community Basercms
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T07:33:53.821Z

Reserved: 2026-09-18T01:11:35.023Z

Link: CVE-2026-93463

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:35.940

Modified: 2026-09-30T08:16:35.940

Link: CVE-2026-93463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')