CVE-2026-21861

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-31 01:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-21861

Mitre link : CVE-2026-21861

CVE.ORG link : CVE-2026-21861


JSON object : View

Products Affected

basercms

  • basercms
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')