baserCMS has a SQL injection vulnerability in blog posts.
baserCMS 5.2.2 and earlier versions
Malicious SQL may be executed in blog posts.
Update to the latest version of baserCMS
Please refer to the following page to reference for more information.
https://basercms.net/security/JVN_52157568
Mirai Matsumoto@Future Secure Wave, Inc.
| Score | Percentile |
|---|---|
| 0.04% | 10.57% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 6.9 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-vh89-rjph-2g7p ↗ |
| CVE | CVE-2026-27697 ↗ |
| CWE id | Name |
|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | baserproject/basercms | <= 5.2.2 | 5.2.3 | — |