Cross-site scripting in baserCMS - CVE-2026-93463
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute scripts in the browsers of visitors.
The vulnerability exists due to improper neutralization of script content in BcValidation::containsScript() when validating user-supplied content. A remote user can store crafted scripts in content to execute scripts in the browsers of visitors.
A visitor must view the stored content.