CVE-2026-30880Disclosure(basercms / basercms)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch basercms basercms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • basercms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-31); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
basercms

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 103-3104-01
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-313
Disclosure2Patch1
2026-04-011
Disclosure1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-30880 📊 Severity: 9.2 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-30880 #CVE-2026-30880 #CVE #Critical #CyberSecurity #InfoSec https://t.co/FOKJzYknR9

    Post summary

    The tweet announces the publication of CVE‑2026‑30880, noting its critical severity and linking to the NVD entry, but provides no further technical or exploit information.

    0001023
    123 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `baserCMS` installer has a critical OS command injection vulnerability (CVE-2026-30880). This could lead to system compromise during initial setup. Review installer security. #infosec #OSInjection #websec https://www.pulsepatch.io/posts/cve-2026-30880-basercms-os-command-injection-installer

    Post summary

    The post announces a critical OS command injection vulnerability in the baserCMS installer that could enable system compromise during initial setup.

    0000046
    6 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30880: baserCM... Installer RCE with 9.2 CVSS means fresh baserCMS deployments = instant shells for attackers scanning setup endpoints. #RCE #installer #baserCMS. https://zerodaysignal.com/vulnerability/CVE-2026-30880 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a high‑severity remote code execution flaw in baserCMS’s installer, highlighting its risk but providing no PoC, exploit, or patch details.

    0000066
    194 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-30880 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched … https://www.cve.org/CVERecord?id=CVE-2026-30880

    Post summary

    CVE‑2026‑30880, an OS command injection vulnerability in baserCMS installer, has been patched; no PoC, exploitation evidence, or false‑positive claim is mentioned.

    0000099
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbasercmsbasercms---

Explore more