SQL injection in baserCMS - #VU152766
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in the public BlogTags API when processing nested contain parameters that enable an associated BlogPosts query. A remote attacker can send a crafted request containing raw SQL conditions to execute arbitrary code.
The SQL injection read primitives apply to MySQL, MariaDB, PostgreSQL, and SQLite; stacked statements and the administrator-account creation chain to code execution are specific to MySQL and MariaDB.