SB2026092941 - Multiple vulnerabilities in baserCMS
Published: September 29, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in UploaderFilesController::view_limited_file() when handling filename path parameters. A remote privileged user can submit a crafted path traversal request to disclose sensitive information.
Route parameter delivery of traversal sequences requires double encoding.
2) Improper Restriction of Excessive Authentication Attempts (CVE-ID: N/A)
CWE-ID: CWE-307 - Improper Restriction of Excessive Authentication Attempts
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass two-factor authentication and gain administrator access.
The vulnerability exists due to improper restriction of excessive authentication attempts in the admin 2FA verification endpoints and TwoFactorAuthenticationsService::verify() when submitting repeated 2FA verification codes. A remote attacker can submit unlimited six-digit code guesses to bypass two-factor authentication and gain administrator access.
Two-factor authentication must be enabled, and exploitation requires knowledge of a valid administrator password within the code validity window.
3) SQL injection (CVE-ID: N/A)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in the public BlogTags API when processing nested contain parameters that enable an associated BlogPosts query. A remote attacker can send a crafted request containing raw SQL conditions to execute arbitrary code.
The SQL injection read primitives apply to MySQL, MariaDB, PostgreSQL, and SQLite; stacked statements and the administrator-account creation chain to code execution are specific to MySQL and MariaDB.
4) Incorrect permission assignment for critical resource (CVE-ID: N/A)
CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to incorrect permission assignment for a critical resource in the bc-mcp plugin's OAuth2Service::generateKeyPair() function when generating the OAuth2 signing key pair. A local user can read the OAuth2 private key and re-sign an access token with altered user_id or scope claims to escalate privileges.
Exploitation requires access to a live, unexpired, and unrevoked token identifier.
5) Cross-site scripting (CVE-ID: CVE-2026-93463)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute scripts in the browsers of visitors.
The vulnerability exists due to improper neutralization of script content in BcValidation::containsScript() when validating user-supplied content. A remote user can store crafted scripts in content to execute scripts in the browsers of visitors.
A visitor must view the stored content.
6) Cross-site scripting (CVE-ID: CVE-2026-93464)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in visitors' browsers.
The vulnerability exists due to improper neutralization of script input in the custom content description and CustomContentHelper::description() when a visitor views a custom content list page. A remote user can store a script in a custom content description to execute arbitrary script in visitors' browsers.
7) Missing Authorization (CVE-ID: CVE-2026-93462)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization checks in BlogCommentsService::getIndex() when handling requests to the public blog comments list API. A remote attacker can send a request to the list endpoint to disclose unapproved comment contents and submitter email addresses.
The issue is limited to the list endpoint; the single-record endpoint applies the comment approval check.
8) SQL injection (CVE-ID: N/A)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements in an SQL command in public Custom Content front actions when handling nested contain query parameters. A remote attacker can send a crafted query parameter to execute arbitrary code.
The application-level code-execution chain requires MySQL or MariaDB.
9) SQL injection (CVE-ID: N/A)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to SQL injection in the BlogPostsService eager-load query handling when processing crafted nested contain query parameters on public blog front routes. A remote attacker can send a specially crafted request to execute arbitrary code.
Stacked data-modification statements and the administrator-creation-to-plugin execution chain are specific to MySQL and MariaDB deployments.
10) Stored cross-site scripting (CVE-ID: CVE-2026-93460)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
Install update from vendor's website.
References
- https://github.com/baserproject/basercms/security/advisories/GHSA-p22r-jcj7-mf93
- https://github.com/baserproject/basercms/blob/9d315389ae0049c81a599638eb4b2a84cb5623f5/plugins/bc-uploader/src/Controller/UploaderFilesController.php
- https://github.com/baserproject/basercms/security/advisories/GHSA-pqvq-3jg5-27x4
- https://github.com/baserproject/basercms/security/advisories/GHSA-v9g2-xmwr-23vc
- https://github.com/baserproject/basercms/security/advisories/GHSA-8qvr-v52m-fj2h
- https://github.com/baserproject/basercms/security/advisories/GHSA-xqr4-p67x-mw3m
- https://github.com/baserproject/basercms/security/advisories/GHSA-m854-6p5c-8g3j
- https://github.com/baserproject/basercms/security/advisories/GHSA-q44m-9xgf-xwmm
- https://github.com/baserproject/basercms/security/advisories/GHSA-2ghw-gwvv-mv56
- https://github.com/baserproject/basercms/security/advisories/GHSA-ch8f-q957-r9xm
- https://jvn.jp/en/jp/JVN14353754/index.html
- https://basercms.net/security/JVN_14353754