Description
Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
Published: 2026-09-30
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑site scripting that enables arbitrary script execution in users' browsers
Action: Update CMS
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw located in the custom content description feature of baserCMS. A malicious actor can inject arbitrary JavaScript that is persisted and rendered when users view the affected content. Execution of that script occurs within the victim's browser, allowing the attacker to perform client‑side attacks such as session hijacking, credential theft, or defacement. This flaw represents a typical reflected input injection weakness (CWE‑79) that can break the integrity and confidentiality of the application.

Affected Systems

The flaw exists in all baserCMS installations that expose the custom content description field for user input. No specific version constraints are listed; therefore any deployment using the default content description mechanism could be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 5.1 places the issue in the moderate severity range. The EPSS score is not available, and the vulnerability is not currently enumerated in the CISA KEV catalog, indicating no confirmed widespread exploitation. Likely attack requires authenticated access to the CMS’s content editing interface or a compromised user account to inject the malicious payload, after which any user who loads the stored content will be affected. The overall risk is considered moderate pending the discovery of a patch or mitigation.

Generated by OpenCVE AI on September 30, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update baserCMS to a version that addresses the stored XSS flaw
  • Configure the CMS to escape or encode custom content descriptions before rendering
  • Deploy a Content Security Policy that disallows inline scripts

Generated by OpenCVE AI on September 30, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting via Custom Content Descriptions in baserCMS

Wed, 30 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Basercms Users Community
Basercms Users Community basercms
Vendors & Products Basercms Users Community
Basercms Users Community basercms

Wed, 30 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Basercms Users Community Basercms
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T07:34:33.353Z

Reserved: 2026-09-18T01:11:35.023Z

Link: CVE-2026-93464

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:36.083

Modified: 2026-09-30T08:16:36.083

Link: CVE-2026-93464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')