CVE-2025-32957Disclosure(basercms / basercms)

LOWCVSS 7.2 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch basercms basercms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using require_once without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included. This issue has been patched in version 5.2.3.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • basercms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
basercms

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-31: 5Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 403-31
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2025-32957 baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automaticall… https://www.cve.org/CVERecord?id=CVE-2025-32957

    Post summary

    The snippet reports that CVE-2025-32957 involves baserCMS’s restore feature allowing .zip uploads, but provides no PoC, exploit details, patch information, or evidence of current exploitation.

    00000134
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-32957 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-32957 #CVE-2025-32957 #CVE #High #CyberSecurity #InfoSec https://t.co/Hg4OhttYq3

    Post summary

    The tweet simply announces the new CVE‑2025‑32957 with severity information, lacking details on exploitation, patches, or technical specifics.

    00000174
    123 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-32957: HIGH] Website developers using baserCMS should update to version 5.2.3 to prevent arbitrary code execution. Prior versions allow attackers to upload malicious PHP files through the restore f...#cve,CVE-2025-32957,#cybersecurity https://cvefind.com/CVE-2025-32957

    Post summary

    The tweet highlights a baserCMS vulnerability (CVE‑2025‑32957) that allows arbitrary code execution via PHP file uploads, and urges developers to patch to version 5.2.3.

    00000101
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-32957 - High baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file i... https://www.thehackerwire.com/vulnerability/CVE-2025-32957/ https://t.co/tPV4trJxrJ

    Post summary

    The post discloses CVE-2025-32957, a vulnerability in baserCMS that allows arbitrary PHP file uploads via the restore function, potentially enabling remote code execution. No proof‑of‑concept, exploit tool, active exploitation, patch, or debunking is mentioned.

    00000227
    163 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-32957 - High baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file i... https://www.thehackerwire.com/vulnerability/CVE-2025-32957/ https://t.co/6HXvxgaVyJ

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2025‑32957) in baserCMS, noting that the restore feature allows uploaded zip files to be extracted and PHP files executed via the automatic extraction process.

    00000232
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbasercmsbasercms---

Explore more