CVE-2026-30878Disclosure(basercms / basercms)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. This issue has been patched in version 5.2.3.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • basercms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
basercms

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-31: 3Technical Details · 2026-03-31: 203-31
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30878 baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when t… https://www.cve.org/CVERecord?id=CVE-2026-30878

    Post summary

    CVE-2026-30878 allows unauthenticated users to submit mail form entries via a public API in baserCMS versions older than 5.2.3; no PoC, patch, or evidence of active exploitation is provided.

    00000103
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-30878 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-30878 #CVE-2026-30878 #CVE #Medium #CyberSecurity #InfoSec https://t.co/KggNH2Zl61

    Post summary

    A tweet simply announces a CVE with a medium severity score, but provides no technical details, PoC, exploit, or patch information.

    0000026
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30878 - baserCMS: Mail Form Acceptance Bypass via Public API Intel Report: https://ift.tt/5W1DAdY

    Post summary

    A newly disclosed vulnerability (CVE-2026-30878) in baserCMS permits bypass of mail form acceptance through the public API; the tweet links to an Intel report but provides no PoC, exploit tool, patch, or evidence of active exploitation.

    0000040
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbasercmsbasercms---

Explore more