HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-21861 — baserCMS is a website development framework. Prior to version 5.2.3, baserCMS co...

Tuesday, March 31, 2026 at 01:16 AM UTC·Source: NIST NVD

Updated: Monday, April 6, 2026 at 12:17 AM UTC

Executive Summary

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in vers

Analysis

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3. CVSS Score: 9.1. Published: 2026-03-31T01:16:35.540.

Indicators of Compromise (1)

CVE (1)
CVE-2026-21861
Source Attribution

Originally published by NIST NVD on Mar 31, 2026. Verified by: NIST.

Related Threats